CVE-2024-28172

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Aug 14, 2024
Updated: Sep 6, 2024
CWE ID 427

Summary

CVE-2024-28172 is a vulnerability affecting Intel(R) Trace Analyzer and Collector software versions prior to 2022.1. This issue permits authenticated users to potentially escalate privileges through an uncontrolled search path. By manipulating the software's search parameters, a local attacker can gain unauthorized access to sensitive data or execute unintended commands, posing a significant risk to system security. Users are advised to update their software to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share