Improper Neutralization of Invalid Characters in Identifiers in Web Pages
CVE-2024-21864
Summary
Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.
- HIGH
- ADJACENT_NETWORK
- HIGH
- CHANGED
- REQUIRED
- NONE
- LOW
- HIGH
CWE-86 - Improper Neutralization of Invalid Characters in Identifiers in Web Pages
The software does not neutralize or incorrectly neutralizes invalid characters or byte sequences in the middle of tag names, URI schemes, and other identifiers.
References
Advisory Timeline
- Published