Improper access control in Intel Arc graphics card A770 and Intel Arc graphics card A750 - CVE-2022-38973

 

Improper access control in Intel Arc graphics card A770 and Intel Arc graphics card A750 - CVE-2022-38973

Published: August 11, 2023


Vulnerability identifier: #VU79389
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38973
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A local user can bypass implemented security restrictions to gain unauthorized access to sensitive information or perform a denial of service (DoS) attack.

Note: This vulnerability affects only graphics cards sold between October of 2022 and December of 2022.


Affected software

Intel Arc graphics card A770
Intel Arc graphics card A750

How to mitigate CVE-2022-38973

Install updates from vendor's website.


External References

Related Security Bulletins