VYPR
Unrated severityNVD Advisory· Published Feb 14, 2024· Updated May 12, 2025

CVE-2023-24542

CVE-2023-24542

Description

Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unquoted search path in Intel Thunderbolt DCH drivers before version 88 allows local authenticated users to escalate privileges.

Vulnerability

The Intel Thunderbolt DCH drivers for Windows before version 88 contain an unquoted search path vulnerability. This occurs when the driver installer or service references a path with spaces without enclosing it in quotes, allowing an attacker to place a malicious executable in a higher-priority directory that Windows searches. Affected versions: all prior to version 88 [1].

Exploitation

An authenticated user with local access can exploit this by placing a crafted executable in a directory that will be searched before the intended file. The attacker does not need special privileges beyond standard user access. The unquoted path is used during driver installation or service startup, triggering the search order [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code with elevated privileges, leading to escalation of privilege. The attacker gains the ability to run code in the context of the driver or system service, potentially compromising the entire system [1].

Mitigation

Intel has released driver version 88 to address this issue. Users should update to version 88 or later via Intel's official channels. No workarounds are documented; the fix is to apply the update. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].

References
  1. INTEL-SA-00851

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.