PT-2024-6975 · Intel · Intel Connectivity Performance Suite

Mohamed Amine Saidani

·

Published

2024-08-13

·

Updated

2024-08-18

·

CVE-2023-43747

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel Connectivity Performance Suite versions prior to 2.0
Description The issue is related to incorrect default permissions in the Intel Connectivity Performance Suite software installer. This could allow an authenticated user to potentially enable escalation of privilege via local access.
Recommendations For versions prior to 2.0, update the software to version 2.0 or later to mitigate the risk of privilege escalation. As a temporary workaround, consider restricting local access to the installer until a patch is applied.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

BDU:2024-08224
CVE-2023-43747

Affected Products

Intel Connectivity Performance Suite