← Vulnerability feed

Vulnerability record · CVE-2023-22355 · published 10 May 2023

CVE-2023-22355: Intel advisor uncontrolled search path element vulnerability

Intel · Advisor

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.

7.8 CVSS 3.1 High EPSS 0.21% · top 90.0% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
29Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22355 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-21772Intel advisor uncontrolled search path element vulnerabilityUncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of …EPSS 0.19%7.8CVE-2023-35121Intel advisor improper access control vulnerabilityImproper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 m…EPSS 0.16%7.8CVE-2023-24592Intel advisor path traversal vulnerabilityPath traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable e…EPSS 0.25%7.8CVE-2022-28696Intel distribution for python uncontrolled search path element vulnerabilityUncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escala…EPSS 0.22%7.8CVE-2022-21128Intel advisor vulnerabilityInsufficient control flow management in the Intel(R) Advisor software before version 7.6.0.37 may allow an authenticated user to potentially enable e…EPSS 0.23%7.8CVE-2021-23152Intel advisor vulnerabilityImproper access control in the Intel(R) Advisor software before version 2021.2 may allow an authenticated user to potentially enable escalation of pr…EPSS 0.24%7.8CVE-2021-33129Intel advisor incorrect default permissions vulnerabilityIncorrect default permissions in the software installer for the Intel(R) Advisor before version 2021.4.0 may allow an authenticated user to potential…EPSS 0.21%7.8CVE-2018-12175Intel distribution for python incorrect default permissions vulnerabilityDefault install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via l…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2023-22355), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.