Untrusted search path in Intel Rapid Storage Technology - CVE-2022-43456
Published: August 10, 2023
Intel Rapid Storage Technology
Intel
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to untrusted search path. A local user can place a malicious binary file on the affected system and execute arbitrary code with elevated privileges.
Remediation
Intel recommends updating Intel® RST software to the latest versions.
Updates are available for download at the following locations:
- Intel® RST Driver Installation Software with Intel® Optane™ Memory
(11th up to 13th Gen Platforms) to version 19.5.2.1049.5 or later:
https://www.intel.com/content/www/us/en/download/720755/ - Intel® RST Driver Installation Software with Intel® Optane™ Memory
(10th and 11th Gen Platforms) to version 18.7.6.1010.3 or later:
https://www.intel.com/content/www/us/en/download/19512 - Intel® RST Driver Installation Software with Intel® Optane™ Memory
(8th and 9th Gen Platforms) to version 17.11.3.1010.2 or later:
https://www.intel.com/content/www/us/en/download/19755 - Intel® RST User Interface and Driver software to version 16.8.5.1014.5 or later:
https://www.intel.com/content/www/us/en/download/15667