CVE-2023-27391

Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
intelCNA
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
inteladvisor_for_oneapi
𝑥
< 2023.1
intelcpu_runtime_for_opencl_applications
𝑥
< 2023.1
inteldistribution_for_python_programming_language
𝑥
< 2023.1
inteldpc\+\+_compatibility_tool
𝑥
< 2023.1
intelembree_ray_tracing_kernel_library
𝑥
< 2023.1
intelfortran_compiler
𝑥
< 2023.1
intelimplicit_spmd_program_compiler
𝑥
< 1.19.1
intelinspector_for_oneapi
𝑥
< 2023.1
intelintegrated_performance_primitives
𝑥
< 2021.8
intelipp_cryptography
𝑥
< 2021.7.0
intelmpi_library
𝑥
< 2021.9.0
inteloneapi_base_toolkit
𝑥
< 2023.1
inteloneapi_data_analytics_library
𝑥
< 2023.1
inteloneapi_deep_neural_network_library
𝑥
< 2023.1
inteloneapi_dpc\+\+\/c\+\+_compiler
𝑥
< 2023.1
inteloneapi_dpc\+\+_library_\(onedpl\)
𝑥
< 2022.1
inteloneapi_hpc_toolkit
𝑥
< 2023.1
inteloneapi_iot_toolkit
𝑥
< 2023.1
inteloneapi_math_kernel_library
𝑥
< 2023.1
inteloneapi_rendering_toolkit
𝑥
< 2023.1
inteloneapi_threading_building_blocks
𝑥
< 2021.9.0
inteloneapi_toolkit_and_component_software_installer
𝑥
< 4.3.1.493
inteloneapi_video_processing_library
𝑥
< 2023.1
intelopen_image_denoise
𝑥
< 1.4.3
intelopen_volume_kernel_library
𝑥
< 2023.1
intelospray
𝑥
< 2023.1
intelospray_studio
𝑥
< 2023.1
inteltrace_analyzer_and_collector
𝑥
< 2021.9.0
intelvtune_profiler_for_oneapi
𝑥
< 2023.1
𝑥
= Vulnerable software versions