Permissions, Privileges, and Access Controls in Intel Endpoint Management Assistant (EMA) - CVE-2022-38056
Published: February 22, 2023
Vulnerability identifier: #VU72497
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38056
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote administrator to escalate privileges on the system.
The vulnerability exists due to improper neutralization, which leads to security restrictions bypass and privilege escalation.
Affected software
Intel Endpoint Management Assistant (EMA)
How to mitigate CVE-2022-38056
Install updates from vendor's website.
Intel Endpoint Management Assistant (EMA) - update to 1.8.1.0