CVE-2024-36245: Medium severity intel vtune profiler for oneapi vulnerability
Published Nov 13, 2024
·Updated
Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
4 affected components
Intel Vtune Profiler<2024.2.0
Intel Oneapi Base Toolkit<2024.2
Intel System Bring-up Toolkit<2024.2.0
Intel Vtune Profiler<2024.2
Event History
Nov 13, 2024
CVE Published
via MITRE·09:11 PM
Data Sourced
via MITRE·09:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36245?
CVE-2024-36245 is classified as a medium severity vulnerability due to its potential for escalation of privilege by authenticated users.
2
Who is affected by CVE-2024-36245?
CVE-2024-36245 affects Intel VTune Profiler software versions prior to 2024.2.0.
3
How do I fix CVE-2024-36245?
To mitigate CVE-2024-36245, upgrade to Intel VTune Profiler version 2024.2.0 or later.
4
What causes CVE-2024-36245?
CVE-2024-36245 is caused by an uncontrolled search path element that could be exploited to escalate privileges.
5
Is local access required to exploit CVE-2024-36245?
Yes, local access is required to exploit CVE-2024-36245 as it affects authenticated users.