CVE-2022-25905

MEDIUM

Intel Oneapi Data Analytics Library - Uncontrolled Search Path

Title source: rule

Description

Uncontrolled search path element in the Intel(R) oneAPI Data Analytics Library (oneDAL) before version 2021.5 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.

Scores

CVSS v3 6.7
EPSS 0.0015
EPSS Percentile 35.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

intel/oneapi_data_analytics_library < 2021.5

Timeline

Published Feb 16, 2023
Tracked Since Feb 18, 2026