MEDIUM · 6.7

CVE-2023-27382

Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable esca...

Vulnerability Description

Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelNuc P14E Laptop Element< 1.0.0.156
MicrosoftWindows 10-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-27382?

CVE-2023-27382 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable esca...

How severe is CVE-2023-27382?

CVE-2023-27382 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-27382?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc P14E Laptop Element, Microsoft Windows 10.