← Vulnerability feed

Vulnerability record · CVE-2024-37027 · published 13 November 2024

CVE-2024-37027: Intel oneapi base toolkit improper input validation vulnerability

Intel · Oneapi Base Toolkit

Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable denial of service via local access.

5.2 CVSS 4.0 Medium EPSS 0.16% · top 95.7% CWE-20 · Improper input validation
5.2CVSS 4.0 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable denial of service via local access.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-37027 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-21772Intel advisor uncontrolled search path element vulnerabilityUncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of …EPSS 0.19%7.8CVE-2023-45320Intel vtune profiler uncontrolled search path element vulnerabilityUncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially en…EPSS 0.18%7.8CVE-2023-35121Intel advisor improper access control vulnerabilityImproper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 m…EPSS 0.16%7.8CVE-2023-24592Intel advisor path traversal vulnerabilityPath traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable e…EPSS 0.25%7.8CVE-2023-29242Intel oneapi ai analytics toolkit improper access control vulnerabilityImproper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation o…EPSS 0.14%7.8CVE-2023-22355Intel advisor uncontrolled search path element vulnerabilityUncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user t…EPSS 0.21%7.8CVE-2022-41982Intel vtune profiler uncontrolled search path element vulnerabilityUncontrolled search path element in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially ena…EPSS 0.17%7.8CVE-2022-41658Intel vtune profiler incorrect permission assignment vulnerabilityInsecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enabl…EPSS 0.15%

Source: NIST National Vulnerability Database (record CVE-2024-37027), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.