Search
Find a vulnerability
Search criteria
2 vulnerabilities by intel_advanced_link_analyzer_standard_edition_software_installer
CVE-2024-37025 (GCVE-0-2024-37025)
Vulnerability from nvd – Published: 2024-11-13 21:11 – Updated: 2024-11-14 14:41
VLAI
EPSS
VEX
Summary
Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Severity
6.7 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-14 14:37 UTC
CWE
- escalation of privilege
- CWE-279 - Incorrect execution-assigned permissions
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | Intel(R) Advanced Link Analyzer Standard Edition software installer |
Affected:
before version 23.1.1
|
|
| intel_advanced_link_analyzer_standard_edition_software_installer | intel_advanced_link_analyzer_standard_edition_software_installer |
Affected:
0 , < 23.1.1
(custom)
cpe:2.3:a:intel_advanced_link_analyzer_standard_edition_software_installer:intel_advanced_link_analyzer_standard_edition_software_installer:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:intel_advanced_link_analyzer_standard_edition_software_installer:intel_advanced_link_analyzer_standard_edition_software_installer:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "intel_advanced_link_analyzer_standard_edition_software_installer",
"vendor": "intel_advanced_link_analyzer_standard_edition_software_installer",
"versions": [
{
"lessThan": "23.1.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-37025",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-14T14:37:59.774293Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-14T14:41:14.729Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Intel(R) Advanced Link Analyzer Standard Edition software installer",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "before version 23.1.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "escalation of privilege",
"lang": "en"
},
{
"cweId": "CWE-279",
"description": "Incorrect execution-assigned permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-13T21:11:55.168Z",
"orgId": "6dda929c-bb53-4a77-a76d-48e79601a1ce",
"shortName": "intel"
},
"references": [
{
"name": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01197.html",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01197.html"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "6dda929c-bb53-4a77-a76d-48e79601a1ce",
"assignerShortName": "intel",
"cveId": "CVE-2024-37025",
"datePublished": "2024-11-13T21:11:55.168Z",
"dateReserved": "2024-06-15T03:00:08.681Z",
"dateUpdated": "2024-11-14T14:41:14.729Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-37025 (GCVE-0-2024-37025)
Vulnerability from cvelistv5 – Published: 2024-11-13 21:11 – Updated: 2024-11-14 14:41
VLAI
EPSS
VEX
Summary
Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Severity
6.7 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-14 14:37 UTC
CWE
- escalation of privilege
- CWE-279 - Incorrect execution-assigned permissions
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| n/a | Intel(R) Advanced Link Analyzer Standard Edition software installer |
Affected:
before version 23.1.1
|
|
| intel_advanced_link_analyzer_standard_edition_software_installer | intel_advanced_link_analyzer_standard_edition_software_installer |
Affected:
0 , < 23.1.1
(custom)
cpe:2.3:a:intel_advanced_link_analyzer_standard_edition_software_installer:intel_advanced_link_analyzer_standard_edition_software_installer:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:intel_advanced_link_analyzer_standard_edition_software_installer:intel_advanced_link_analyzer_standard_edition_software_installer:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "intel_advanced_link_analyzer_standard_edition_software_installer",
"vendor": "intel_advanced_link_analyzer_standard_edition_software_installer",
"versions": [
{
"lessThan": "23.1.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-37025",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-14T14:37:59.774293Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-14T14:41:14.729Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Intel(R) Advanced Link Analyzer Standard Edition software installer",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "before version 23.1.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "LOCAL",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "escalation of privilege",
"lang": "en"
},
{
"cweId": "CWE-279",
"description": "Incorrect execution-assigned permissions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-13T21:11:55.168Z",
"orgId": "6dda929c-bb53-4a77-a76d-48e79601a1ce",
"shortName": "intel"
},
"references": [
{
"name": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01197.html",
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01197.html"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "6dda929c-bb53-4a77-a76d-48e79601a1ce",
"assignerShortName": "intel",
"cveId": "CVE-2024-37025",
"datePublished": "2024-11-13T21:11:55.168Z",
"dateReserved": "2024-06-15T03:00:08.681Z",
"dateUpdated": "2024-11-14T14:41:14.729Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}