CVE-2024-31073 Details
Description
Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially enable escalation of privilege via local access.
A vulnerability in some Intel oneAPI Level Zero software prior to version 1.5.4 may allow an authenticated user to escalate privileges through local access. This issue arises from an uncontrolled search path in the software.
Users are advised to update Intel oneAPI Level Zero software to version 1.5.4 or later. The latest version can be downloaded from the Intel oneAPI Level Zero GitHub releases page. For Intel Graphics Windows DCH drivers, updates are available through the Intel Download Center. Intel Arc and Iris Xe Graphics for Windows users should also update to the latest version available on the Intel Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2025CISA-ADP
Assessed May 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01274.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intel oneAPI Level Zero | All versions |
CPE
Remediation
| |
| Intel Graphics Windows DCH driver | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2025 | New CVE Received | [email protected] |
Volerion