PT-2020-4941 · Intel · Intel Battery Life Diagnostic Tool

Published

2020-11-10

·

Updated

2020-11-24

·

CVE-2020-12346

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Intel Battery Life Diagnostic Tool versions prior to 1.0.7
Description: The issue is related to improper permissions in the installer for the Intel Battery Life Diagnostic Tool, which may allow an authenticated user to potentially enable escalation of privilege via local access. This is due to errors in using standard permissions.
Recommendations: For versions prior to 1.0.7, update to version 1.0.7 or later to resolve the issue. As a temporary workaround, consider restricting local access to the tool until a patch is applied.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05516
CVE-2020-12346

Affected Products

Intel Battery Life Diagnostic Tool