Skip to main content

Improper Neutralization of Invalid Characters in Identifiers in Web Pages

CVE-2024-21864

Severity High
Score 7.8/10

Summary

Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.

  • HIGH
  • ADJACENT_NETWORK
  • HIGH
  • CHANGED
  • REQUIRED
  • NONE
  • LOW
  • HIGH

CWE-86 - Improper Neutralization of Invalid Characters in Identifiers in Web Pages

The software does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.

References

Advisory Timeline

  • Published