CVE-2024-28172: High severity intel oneapi hpc toolkit vulnerability
Published Aug 14, 2024
·Updated
Uncontrolled search path for some Intel(R) Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
2 affected components
Intel oneAPI HPC Toolkit<2024.1.0
Intel Trace Analyzer and Collector<2022.1
Event History
Aug 14, 2024
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28172?
CVE-2024-28172 has a high severity rating due to potential escalation of privilege risks.
2
How do I fix CVE-2024-28172?
To mitigate CVE-2024-28172, upgrade to Intel Trace Analyzer and Collector version 2022.1 or later.
3
Who is affected by CVE-2024-28172?
CVE-2024-28172 affects users of Intel's Trace Analyzer and Collector and Intel oneAPI HPC Toolkit prior to specified versions.
4
What type of vulnerability is CVE-2024-28172?
CVE-2024-28172 is classified as an uncontrolled search path vulnerability that could lead to privilege escalation.
5
Can an unauthenticated user exploit CVE-2024-28172?
CVE-2024-28172 requires authenticated access, so it cannot be exploited by unauthenticated users.