PT-2024-7024 · Microsoft+1 · Windows+2

Mohammed

·

Published

2024-08-13

·

Updated

2024-08-14

·

CVE-2024-21769

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel Ethernet Adapter Complete Driver Pack versions (affected versions not specified) Intel(R) Ethernet Connection I219-LM (affected versions not specified)
Description The issue is related to an uncontrolled search path element in the installer for Intel Ethernet Adapter Complete Driver Pack for the Windows operating system. This could potentially allow an authenticated user to escalate their privileges via local access.
Recommendations For Intel Ethernet Adapter Complete Driver Pack, consider restricting access to the installer until a patch is available. For Intel(R) Ethernet Connection I219-LM, as a temporary workaround, consider disabling the installation software until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-08278
CVE-2024-21769

Affected Products

Intel Ethernet Adapter Complete Driver Pack
Intel(R) Ethernet Connection I219-Lm
Windows