#VU63541 Untrusted search path in Intel Extreme Tuning Utility (XTU) - CVE-2022-22139
Published: May 23, 2022
Intel Extreme Tuning Utility (XTU)
Intel
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path when loading libraries. A local user can place a malicious .dll file into a specific directory, trick another system user to launch software from that directory and execute arbitrary code with elevated privileges.