CVE-2017-5682
Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel Library, Intel Data Analytics Acceleration Library, and Intel Threading Building Blocks before 2017 Update 2 allows an attacker to launch a process with escalated privileges.
- CVSS 3.0
- 7.3 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Affected
- intel/advisor · intel/cryptography for intel integrated performance primitives · intel/data analytics acceleration library · intel/inspector · intel/integrated performance primitives · intel/math kernel library · intel/mpi library · intel/parallel studio xe · intel/system studio · intel/threading building blocks · intel/trace analyzer and collector · intel/vtune amplifier
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/96482Third Party Advisory, VDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00070&languageid=en-frVendor Advisory
- http://www.securityfocus.com/bid/96482Third Party Advisory, VDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00070&languageid=en-frVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.