VYPR
Unrated severityNVD Advisory· Published Feb 14, 2024· Updated May 12, 2025

CVE-2023-22293

CVE-2023-22293

Description

Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper access control in Intel Thunderbolt DCH drivers for Windows allows authenticated users to escalate privileges locally.

Vulnerability

An improper access control vulnerability exists in the Intel(R) Thunderbolt(TM) DCH drivers for Windows. This flaw allows an authenticated user to potentially escalate privileges via local access. The vulnerability resides in the driver's handling of access controls, which may be bypassed under certain conditions. Affected versions include those prior to the fixed release provided in Intel advisory INTEL-SA-00851 [1].

Exploitation

An attacker must have local access to the system and be authenticated as a user. The exploitation does not require any special privileges beyond normal user access. The attacker can exploit the improper access control to execute operations that should be restricted, leading to privilege escalation. The exact steps involve leveraging the driver's flawed access control mechanism to gain elevated permissions.

Impact

Successful exploitation allows an authenticated attacker to escalate privileges on the affected system. This could result in the attacker gaining administrative or system-level privileges, potentially leading to full compromise of the confidentiality, integrity, and availability of the system.

Mitigation

Intel has released updates to address this vulnerability. Users should update to the latest version of the Intel Thunderbolt DCH drivers as indicated in Intel advisory INTEL-SA-00851 [1]. No workarounds are mentioned in the available references. If the system is not updated, it remains vulnerable to local privilege escalation.

References
  1. INTEL-SA-00851

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.