CVE-2024-21766: Medium severity intel oneapi math kernel library vulnerability
Published Aug 14, 2024
·Updated
Uncontrolled search path for some Intel(R) oneAPI Math Kernel Library software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
1 affected component
Intel oneAPI Math Kernel Library<2024.1
Event History
Aug 14, 2024
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-21766?
CVE-2024-21766 is classified as a high severity vulnerability due to the potential for privilege escalation.
2
How do I fix CVE-2024-21766?
The recommended fix for CVE-2024-21766 is to upgrade to Intel oneAPI Math Kernel Library version 2024.1 or later.
3
Who is affected by CVE-2024-21766?
CVE-2024-21766 affects users of Intel oneAPI Math Kernel Library versions earlier than 2024.1.
4
What types of attacks can CVE-2024-21766 facilitate?
CVE-2024-21766 can facilitate privilege escalation attacks for authenticated users with local access.
5
Is authentication required to exploit CVE-2024-21766?
Yes, exploitation of CVE-2024-21766 requires authentication as it affects authenticated users.