CVE-2024-36280: Medium severity intel high level synthesis compiler vulnerability
Published Feb 12, 2025
·Updated
Uncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
1 affected component
Intel High Level Synthesis Compiler<24.2
Event History
Feb 12, 2025
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36280?
CVE-2024-36280 has a moderate severity rating due to the potential for privilege escalation.
2
How do I fix CVE-2024-36280?
To fix CVE-2024-36280, upgrade to version 24.2 or later of the Intel High Level Synthesis Compiler.
3
Who is affected by CVE-2024-36280?
CVE-2024-36280 affects users of Intel High Level Synthesis Compiler versions prior to 24.2.
4
What type of vulnerability is CVE-2024-36280?
CVE-2024-36280 is classified as an uncontrolled search path vulnerability.
5
Can CVE-2024-36280 be exploited remotely?
CVE-2024-36280 requires local access to exploit and cannot be exploited remotely.