PT-2024-8850 · Intel · Intel Driver & Support Assistant

Published

2024-06-19

·

Updated

2024-11-22

·

CVE-2024-36488

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Intel Driver & Support Assistant versions prior to 24.3.26.8
Description: The issue is related to improper access control in Intel Driver & Support Assistant, which may allow an authenticated user to potentially enable escalation of privilege via local access. This could permit a local attacker to escalate privileges on affected installations.
Recommendations: For versions prior to 24.3.26.8, update to version 24.3.26.8 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-10486
CVE-2024-36488
ZDI-24-1613

Affected Products

Intel Driver & Support Assistant