← Vulnerability feed

Vulnerability record · CVE-2024-21784 · published 14 August 2024

CVE-2024-21784: Intel integrated performance primitives cryptography uncontrolled search path element vulnerability

Intel · Integrated Performance Primitives Cryptography

Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

5.4 CVSS 4.0 Medium EPSS 0.15% · top 96.5% CWE-427 · Uncontrolled search path element
5.4CVSS 4.0 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-21784 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-21772Intel advisor uncontrolled search path element vulnerabilityUncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of …EPSS 0.19%7.8CVE-2023-35121Intel advisor improper access control vulnerabilityImproper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 m…EPSS 0.16%7.8CVE-2023-24592Intel advisor path traversal vulnerabilityPath traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable e…EPSS 0.25%7.8CVE-2023-29242Intel oneapi ai analytics toolkit improper access control vulnerabilityImproper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation o…EPSS 0.14%7.8CVE-2023-22355Intel advisor uncontrolled search path element vulnerabilityUncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user t…EPSS 0.21%7.5CVE-2022-26083Intel integrated performance primitives cryptography vulnerabilityGeneration of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to …EPSS 0.18%7.3CVE-2023-28823Intel advisor for oneapi uncontrolled search path element vulnerabilityUncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user t…EPSS 0.17%6.8CVE-2023-27383Intel advisor vulnerabilityProtection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a privileged…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2024-21784), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.