CVE-2024-23907
—CVSS 4.0
5.4 medium
EPSS
<1%p4
Published
()
Modified
Description
Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
- Vendors
- intel
- Products
- high level synthesis compiler, oneapi dpc\+\+\/c\+\+ compiler, quartus prime
- Weakness
- CWE-427
- Vector
- CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.