CVE-2023-33870
14.02.2024, 14:15
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.Enginsight
Vendor | Product | Version |
---|---|---|
intel | administrative_tools_for_intel_network_adapters | 𝑥 < 28.2 |
intel | ethernet_connections_boot_utility\,_preboot_images\,_and_efi_drivers | 𝑥 < 28.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-277 - Insecure Inherited PermissionsA product defines a set of insecure permissions that are inherited by objects that are created by the program.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.