Impact
An uncontrolled search path flaw in Intel’s Hardware‑Aware‑Automated‑MachineLearning allows an unprivileged user, when collaborating with a privileged user and employing a low‑complexity local attack, to elevate their privileges. The vulnerability exposes the system to a high confidentiality, integrity, and availability impact if successful, potentially permitting the attacker to access protected data, tamper with system settings, and disrupt operations.
Affected Systems
Intel’s Hardware‑Aware‑Automated‑MachineLearning, any release before the code commit 45cd723.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires local access with a privileged user context, a low attack complexity, and only passive user interaction. If an attacker succeeds, they could achieve privilege escalation that compromises confidentiality, integrity, and availability of the affected system. This weakness aligns with CWE‑427, underscoring the risk of uncontrolled path resolution.
OpenCVE Enrichment