CVE-2023-50197: (0Day) Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the DSA Service. By creating a symbolic link, an attacker can abuse the service to write a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21845.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50197?
CVE-2023-50197 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2023-50197?
To fix CVE-2023-50197, update to the latest version of Intel Driver & Support Assistant provided by Intel.
What does CVE-2023-50197 affect?
CVE-2023-50197 affects installations of Intel Driver & Support Assistant.
Can CVE-2023-50197 be exploited remotely?
No, CVE-2023-50197 can only be exploited by local attackers who have low-privilege access.
What are the potential consequences of exploiting CVE-2023-50197?
Exploiting CVE-2023-50197 can allow an attacker to escalate their privileges on the affected system.