PT-2021-12908 · Intel · Intel Rapid Storage Technology

Marius Gabriel Mihai

·

Published

2021-06-09

·

Updated

2021-06-28

·

CVE-2021-0104

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Intel(R) Rapid Storage Technology software versions prior to 17.9.0.34 Intel(R) Rapid Storage Technology software versions prior to 18.0.0.640 Intel(R) Rapid Storage Technology software versions prior to 18.1.0.24
Description: The issue is related to an uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software. This may allow an authenticated user to potentially enable escalation of privilege via local access.
Recommendations: For versions prior to 17.9.0.34, update to version 17.9.0.34 or later. For versions prior to 18.0.0.640, update to version 18.0.0.640 or later. For versions prior to 18.1.0.24, update to version 18.1.0.24 or later.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-0104

Affected Products

Intel Rapid Storage Technology