VYPR
Unrated severityNVD Advisory· Published Feb 16, 2023· Updated Jan 27, 2025

CVE-2022-26345

CVE-2022-26345

Description

Uncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Uncontrolled search path in Intel oneAPI Toolkit OpenMP before 2022.1 allows local authenticated users to escalate privileges.

Vulnerability

An uncontrolled search path element exists in the Intel(R) oneAPI Toolkit OpenMP component prior to version 2022.1 [1]. This vulnerability occurs when the software searches for dynamic libraries in an unsafe order, allowing an attacker with local access to place a malicious DLL in a directory that is searched before the intended path. The affected versions are all releases before 2022.1.

Exploitation

An authenticated user with local access can exploit this vulnerability by placing a specially crafted library in a location that is searched by the vulnerable OpenMP component. When the component loads, it will inadvertently load the malicious library instead of the legitimate one. No additional privileges or user interaction beyond authentication is required, but the attacker must have write access to the target directory.

Impact

Successful exploitation leads to escalation of privilege. The attacker gains the ability to execute arbitrary code with the privileges of the vulnerable process, potentially achieving SYSTEM or administrator-level access. This could result in full compromise of the affected system.

Mitigation

Intel has addressed this issue in oneAPI Toolkit OpenMP version 2022.1 [1]. Users should update to this version or later. No workaround is available for earlier versions.

References
  1. INTEL-SA-00674

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

6

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.