Untrusted search path in Intel Extreme Tuning Utility (XTU) - CVE-2022-22139

 

Untrusted search path in Intel Extreme Tuning Utility (XTU) - CVE-2022-22139

Published: May 23, 2022


Vulnerability identifier: #VU63541
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22139
CWE-ID: CWE-426
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to usage of an untrusted search path when loading libraries. A local user can place a malicious .dll file into a specific directory, trick another system user to launch software from that directory and execute arbitrary code with elevated privileges.


Affected software

Intel Extreme Tuning Utility (XTU)
Alienware Command Center

How to mitigate CVE-2022-22139

Install updates from vendor's website.

Intel Extreme Tuning Utility (XTU) - update to 7.3.0.33
Alienware Command Center - update to 5.5.8.0

External References

Related Security Bulletins