CVE-2018-3668 describes a local privilege escalation vulnerability in Intel Processor Diagnostic Tool (IPDT) versions prior to 4.1.0.27, caused by unquoted service paths. This allows a local attacker to execute arbitrary code with elevated privileges. The vulnerability has a CVSS score of 7.8 (High), indicating a low attack complexity and high impact on confidentiality, integrity, and availability. There is no known exploit code publicly available, nor is it listed on the CISA KEV catalog, suggesting it is not actively exploited, though it has received some media coverage and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.0.27CPE matchmatch criteria | cpe:2.3:a:intel:processor_diagnostic_tool:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.