Description Preview
Overview
This vulnerability affects the installer component of Intel's Computing Improvement Program software. When the installer runs with elevated privileges, it fails to properly set or maintain secure permissions on certain files or directories. As a result, a local authenticated user could potentially exploit these improper permissions to gain elevated privileges on the system. This type of vulnerability is particularly concerning in multi-user environments where privilege boundaries need to be strictly maintained.
Remediation
To address this vulnerability, users should update to Intel Computing Improvement Program software version 2.4.5982 or later. Intel has released this updated version which corrects the permission issues in the installer. Organizations should prioritize this update on systems where multiple users with different privilege levels have access. If immediate updating is not possible, consider restricting local access to trusted users only until the update can be applied.
References
- Intel Security Advisory: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00530.html
- CVE-2021-0074 details in the National Vulnerability Database
- CWE-281: Improper Preservation of Permissions
Industry ExposureMost to leastThis section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.
- ManufacturingManufacturing
- Educational ServicesEducational Services
- Health Care & Social AssistanceHealth Care & Social Assistance
- Other Services (except Public Administration)Other Services (except Public Administration)
- Professional, Scientific, & Technical ServicesProfessional, Scientific, & Technical Services
- Public AdministrationPublic Administration
- UtilitiesUtilities
- Accommodation & Food ServicesAccommodation & Food Services
- Administrative, Support, Waste Management & Remediation ServicesAdministrative, Support, Waste Management & Remediation Services
- Agriculture, Forestry Fishing & HuntingAgriculture, Forestry Fishing & Hunting
- Arts, Entertainment & RecreationArts, Entertainment & Recreation
- ConstructionConstruction
- Finance and InsuranceFinance and Insurance
- InformationInformation
- Management of Companies & EnterprisesManagement of Companies & Enterprises
- MiningMining
- Real Estate Rental & LeasingReal Estate Rental & Leasing
- Retail TradeRetail Trade
- Transportation & WarehousingTransportation & Warehousing
- Wholesale TradeWholesale Trade