CVE-2024-35201
Last modified
CVE-2024-35201 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Server Debug And Provisioning Tool | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-35201?
How severe is CVE-2024-35201?
How do I fix CVE-2024-35201?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-35196Sentry is a developer-first error tracking and performance m…2
- CVE-2024-35197gitoxide is a pure Rust implementation of Git. On Windows, f…5.4
- CVE-2024-35198TorchServe is a flexible and easy-to-use tool for serving an…9.8
- CVE-2024-35199TorchServe is a flexible and easy-to-use tool for serving an…8.2
- CVE-2024-3520The Country State City Dropdown CF7 plugin for WordPress is …4.3
- CVE-2024-35200When NGINX Plus or NGINX OSS are configured to use the HTTP/…5.3
- CVE-2024-35202Bitcoin Core before 25.0 allows remote attackers to cause a …7.5
- CVE-2024-35203Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-sit…6.1
- CVE-2024-35204Veritas System Recovery before 23.3_Hotfix has incorrect per…8.4
- CVE-2024-35205The WPS Office (aka cn.wps.moffice_eng) application before 1…7.8
- CVE-2024-35206A vulnerability has been identified in SINEC Traffic Analyze…8.5
- CVE-2024-35207A vulnerability has been identified in SINEC Traffic Analyze…7.8
Are you affected by CVE-2024-35201?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
