PT-2024-1329 · Intel · Intel Nuc Pro Software Suite

Sim0Nsecurity

·

Published

2024-01-09

·

Updated

2024-01-30

·

CVE-2023-32272

CVSS v3.1

7.9

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel NUC Pro Software Suite versions prior to 3.0.0.6
Description The issue is related to an uncontrolled search path element in the Intel NUC Pro Software Suite Configuration Tool software installers. This could potentially allow an authenticated user to enable denial of service via local access.
Recommendations For versions prior to 3.0.0.6, update to version 3.0.0.6 or later to resolve the issue. As a temporary workaround, consider restricting local access to the Configuration Tool to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-00783
CVE-2023-32272

Affected Products

Intel Nuc Pro Software Suite