Untrusted search path in Intel Extreme Tuning Utility (XTU) - CVE-2022-22139
Published: May 23, 2022
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path when loading libraries. A local user can place a malicious .dll file into a specific directory, trick another system user to launch software from that directory and execute arbitrary code with elevated privileges.
Affected software
Alienware Command Center
How to mitigate CVE-2022-22139
Alienware Command Center - update to 5.5.8.0