CVE-2023-28823
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
Published:Aug 11, 2023
Last Modified:Nov 21, 2024
EPS:Aug 11, 2023
EPSS Score:0.00062
CVSS Score:6.7
Affected Products
Vendor
Product
Action
Vendor
Intel
Product
Advisor For Oneapi
Intel
Advisor For Oneapi
Vendor
Intel
Product
Cpu Runtime For Opencl Applications
Intel
Cpu Runtime For Opencl Applications
Vendor
Intel
Product
Distribution For Python Programming Language
Intel
Distribution For Python Programming Language
Vendor
Intel
Product
Dpc\+\+ Compatibility Tool
Intel
Dpc\+\+ Compatibility Tool
Vendor
Intel
Product
Embree Ray Tracing Kernel Library
Intel
Embree Ray Tracing Kernel Library
Vendor
Intel
Product
Fortran Compiler
Intel
Fortran Compiler
Vendor
Intel
Product
Implicit Spmd Program Compiler
Intel
Implicit Spmd Program Compiler
Vendor
Intel
Product
Inspector For Oneapi
Intel
Inspector For Oneapi
Vendor
Intel
Product
Integrated Performance Primitives
Intel
Integrated Performance Primitives
Vendor
Intel
Product
Ipp Cryptography
Intel
Ipp Cryptography
Vendor
Intel
Product
Mpi Library
Intel
Mpi Library
Vendor
Intel
Product
Oneapi Base Toolkit
Intel
Oneapi Base Toolkit
Vendor
Intel
Product
Oneapi Data Analytics Library
Intel
Oneapi Data Analytics Library
Vendor
Intel
Product
Oneapi Deep Neural Network Library
Intel
Oneapi Deep Neural Network Library
Vendor
Intel
Product
Oneapi Dpc\+\+\/c\+\+ Compiler
Intel
Oneapi Dpc\+\+\/c\+\+ Compiler
Vendor
Intel
Product
Oneapi Dpc\+\+ Library \(onedpl\)
Intel
Oneapi Dpc\+\+ Library \(onedpl\)
Vendor
Intel
Product
Oneapi Hpc Toolkit
Intel
Oneapi Hpc Toolkit
Vendor
Intel
Product
Oneapi Iot Toolkit
Intel
Oneapi Iot Toolkit
Vendor
Intel
Product
Oneapi Math Kernel Library
Intel
Oneapi Math Kernel Library
Vendor
Intel
Product
Oneapi Rendering Toolkit
Intel
Oneapi Rendering Toolkit
Vendor
Intel
Product
Oneapi Threading Building Blocks
Intel
Oneapi Threading Building Blocks
Vendor
Intel
Product
Oneapi Toolkit And Component Software Installer
Intel
Oneapi Toolkit And Component Software Installer
Vendor
Intel
Product
Oneapi Video Processing Library
Intel
Oneapi Video Processing Library
Vendor
Intel
Product
Open Image Denoise
Intel
Open Image Denoise
Vendor
Intel
Product
Open Volume Kernel Library
Intel
Open Volume Kernel Library
Vendor
Intel
Product
Ospray
Intel
Ospray
Vendor
Intel
Product
Ospray Studio
Intel
Ospray Studio
Vendor
Intel
Product
Trace Analyzer And Collector
Intel
Trace Analyzer And Collector
Vendor
Intel
Product
Vtune Profiler For Oneapi
Intel
Vtune Profiler For Oneapi
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
