VYPR
Unrated severityNVD Advisory· Published Feb 14, 2024· Updated Aug 14, 2024

CVE-2023-28715

CVE-2023-28715

Description

Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable denial of service via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper access control in Intel oneAPI Toolkit installers before 4.3.2 allows an authenticated local user to trigger denial of service.

Vulnerability

An improper access control vulnerability exists in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 [1]. The issue arises from insufficient access controls during the installation process, which an authenticated user with local access can exploit to potentially cause a denial of service condition [1].

Exploitation

An attacker must have local access to the system and valid authentication credentials. No special privileges beyond standard user access are required. The exploitation involves taking advantage of the flawed access control mechanisms to disrupt the normal operation of the installer or related components, leading to a denial of service [1].

Impact

Successful exploitation results in a denial of service (DoS) condition, affecting the availability of the Intel oneAPI Toolkit or its components [1]. The impact is limited to local system availability; no data confidentiality or integrity compromise is described in the available references.

Mitigation

Intel has released Intel oneAPI Toolkit version 4.3.2 or later to address this issue [1]. Users are advised to update to the latest version to mitigate the vulnerability. There are no indications that this CVE is listed in the Known Exploited Vulnerabilities (KEV) catalog.

References
  1. INTEL-SA-00956

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Intel(R)/oneAPI Toolkit and component software installersdescription
  • Range: <4.3.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.