CVE-2024-28876 describes an uncontrolled search path vulnerability in Intel MPI Library software versions prior to 2021.12, and Intel oneAPI HPC Toolkit, which could allow an authenticated local user to escalate privileges. This vulnerability carries a CVSS score of 7.3 (HIGH), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2021.12CPE matchmatch criteria | cpe:2.3:a:intel:mpi_library:*:*:*:*:*:*:*:* | ||
< 2024.1CPE matchmatch criteria | cpe:2.3:a:intel:oneapi_hpc_toolkit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.