CVE-2024-28952: Medium severity Intel IPP vulnerability
Uncontrolled search path for some Intel(R) IPP software for Windows before version 2021.12.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Intel(R) IPP software for Windowsto a version that resolves this vulnerability.Fixed in 2021.12.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28952?
CVE-2024-28952 has a moderate severity rating due to the potential for privilege escalation.
How do I fix CVE-2024-28952?
To fix CVE-2024-28952, update the Intel IPP software to version 2021.12.0 or later.
Who is affected by CVE-2024-28952?
Users of Intel IPP software for Windows versions prior to 2021.12.0 are affected by CVE-2024-28952.
What type of vulnerability is CVE-2024-28952?
CVE-2024-28952 is classified as an uncontrolled search path vulnerability.
Can CVE-2024-28952 be exploited remotely?
CVE-2024-28952 requires local access to exploit, as it is aimed at authenticated users.