CVE-2024-36488
Last modified
CVE-2024-36488 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Driver \& Support Assistant | < 24.3.26.8 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-36488?
How severe is CVE-2024-36488?
How do I fix CVE-2024-36488?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-36480Use of hard-coded credentials issue exists in Ricoh Streamli…9.8
- CVE-2024-36481In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-36482Improper input validation in some Intel(R) CIP software befo…6.7
- CVE-2024-36484In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-36485Zohocorp ManageEngine ADAudit Plus versions below 8121 are v…8.8
- CVE-2024-36486A privilege escalation vulnerability exists in the virtual m…7.8
- CVE-2024-36489In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-3649The Contact Form by WPForms – Drag & Drop Form Builder for W…5.3
- CVE-2024-36491FutureNet NXR series, VXR series and WXR series provided by …9.8
- CVE-2024-36492Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <=…6.4
- CVE-2024-36493A stack-based buffer overflow vulnerability exists in the wi…7.2
- CVE-2024-36494Due to missing input sanitization, an attacker can perform c…4.7
Are you affected by CVE-2024-36488?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
