Skip to main content

Uncontrolled Search Path Element

CVE-2023-32272

Severity High
Score 7.9/10

Summary

Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.0.6 may allow an authenticated user to potentially enable denial of service via local access.

  • LOW
  • LOCAL
  • HIGH
  • CHANGED
  • REQUIRED
  • LOW
  • NONE
  • HIGH

CWE-427 - Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

References

Advisory Timeline

  • Published