Vulnerability Description
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Advisor For Oneapi | < 2023.1 |
| Intel | Cpu Runtime For Opencl Applications | < 2023.1 |
| Intel | Distribution For Python Programming Language | < 2023.1 |
| Intel | Dpc\+\+ Compatibility Tool | < 2023.1 |
| Intel | Embree Ray Tracing Kernel Library | < 2023.1 |
| Intel | Fortran Compiler | < 2023.1 |
| Intel | Implicit Spmd Program Compiler | < 1.19.1 |
| Intel | Inspector For Oneapi | < 2023.1 |
| Intel | Integrated Performance Primitives | < 2021.8 |
| Intel | Ipp Cryptography | < 2021.7.0 |
| Intel | Mpi Library | < 2021.9.0 |
| Intel | Oneapi Base Toolkit | < 2023.1 |
| Intel | Oneapi Data Analytics Library | < 2023.1 |
| Intel | Oneapi Deep Neural Network Library | < 2023.1 |
| Intel | Oneapi Dpc\+\+\/C\+\+ Compiler | < 2023.1 |
| Intel | Oneapi Dpc\+\+ Library \(Onedpl\) | < 2022.1 |
| Intel | Oneapi Hpc Toolkit | < 2023.1 |
| Intel | Oneapi Iot Toolkit | < 2023.1 |
| Intel | Oneapi Math Kernel Library | < 2023.1 |
| Intel | Oneapi Rendering Toolkit | < 2023.1 |
Related Weaknesses (CWE)
References
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.hVendor Advisory
- http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.hVendor Advisory
FAQ
What is CVE-2023-27391?
CVE-2023-27391 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local a...
How severe is CVE-2023-27391?
CVE-2023-27391 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-27391?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Advisor For Oneapi, Intel Cpu Runtime For Opencl Applications, Intel Distribution For Python Programming Language, Intel Dpc\+\+ Compatibility Tool, Intel Embree Ray Tracing Kernel Library.