ZeroHour

CVE-2024-23907

CVSS 4.0
5.4 medium
EPSS
<1%p4
Published
()
Modified
Description

Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

Vendors
intel
Products
high level synthesis compiler, oneapi dpc\+\+\/c\+\+ compiler, quartus prime
Weakness
CWE-427
Vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.