VYPR
Unrated severityNVD Advisory· Published Feb 14, 2024· Updated Aug 7, 2024

CVE-2023-32618

CVE-2023-32618

Description

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An uncontrolled search path in Intel oneAPI Toolkit installers before v4.3.2 allows local authenticated users to escalate privileges.

Vulnerability

An uncontrolled search path vulnerability exists in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2. The affected installers may load unintended dynamic-link libraries (DLLs) from insecure search paths, enabling an attacker with local access and valid credentials to subvert the installation process [1].

Exploitation

An attacker must have local access to the system and valid authentication credentials. Exploitation requires the attacker to place a malicious DLL in a directory that the installer searches before the intended system directory, causing the installer to load the attacker's DLL instead of the legitimate one. No user interaction beyond initiating the installer is needed [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code with the privileges of the installer process, potentially leading to escalation of privilege on the affected system. The attacker can achieve arbitrary code execution in the context of the installer, which typically runs with elevated permissions [1].

Mitigation

The vulnerability is fixed in Intel oneAPI Toolkit and component software installers version 4.3.2 and later. Users should update to the latest version available on Intel's official website. No workaround is documented by Intel. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date [1].

References
  1. INTEL-SA-00956

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Intel(R)/oneAPI Toolkit and component software installersdescription
  • Range: <4.3.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.