Untrusted search path in Intel products - CVE-2024-26017
Published: November 13, 2024
Vulnerability identifier: #VU100423
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26017
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path. A local user can gain elevated privileges on the target system.
Affected software
Intel Open Path Guiding Library (Intel Open PGL)
Intel Embree
Intel Rendering Toolkit
Intel OSPRay Studio
Intel Open Volume Kernel Library
Intel Open Image Denoise
Intel OSPRay
Intel Embree
Intel Rendering Toolkit
Intel OSPRay Studio
Intel Open Volume Kernel Library
Intel Open Image Denoise
Intel OSPRay
How to mitigate CVE-2024-26017
Install updates from vendor's website.
Intel Open Path Guiding Library (Intel Open PGL) - update to 0.6.0
Intel OSPRay Studio - update to 1.0.0
Intel Open Volume Kernel Library - update to 2.0.1
Intel Open Image Denoise - update to 2.2.0
Intel OSPRay - update to 3.1.0
Intel Embree - update to 4.3.1
Intel Rendering Toolkit - update to 2024.1.0
Intel OSPRay Studio - update to 1.0.0
Intel Open Volume Kernel Library - update to 2.0.1
Intel Open Image Denoise - update to 2.2.0
Intel OSPRay - update to 3.1.0
Intel Embree - update to 4.3.1
Intel Rendering Toolkit - update to 2024.1.0