PT-2023-12831 · Intel · Intel(R) Oneapi Data Analytics Library

Nikolay Petrov

·

Published

2023-02-16

·

Updated

2023-02-28

·

CVE-2022-25905

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) oneAPI Data Analytics Library (oneDAL) versions prior to 2021.5
Description The issue is related to an uncontrolled search path element in the Intel(R) oneAPI Data Analytics Library (oneDAL), which may allow an authenticated user to potentially enable escalation of privilege via local access.
Recommendations For versions prior to 2021.5, update to version 2021.5 or later to resolve the issue.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2022-25905

Affected Products

Intel(R) Oneapi Data Analytics Library