CVE-2024-37027
MEDIUMIntel VTune Profiler < 2024.2.0 - Authenticated Denial of Service via Improper Input Validation
Title source: llmDescription
Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable denial of service via local access.
References (1)
Core 1
Core References
Scores
CVSS v3
6.1
EPSS
0.0012
EPSS Percentile
30.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (3)
intel/oneapi_base_toolkit
< 2024.2
intel/system_bring-up_toolkit
< 2024.2.0
intel/vtune_profiler
< 2024.2
Published
Nov 13, 2024
Tracked Since
Feb 18, 2026