Impact
The vulnerability stems from a protection mechanism failure in the Intel Transfer Learning Tool. An unauthenticated user, with low complexity attack skills, can trigger an escalation of privilege without needing user interaction. The flaw allows an unprivileged application to gain higher privileges. The potential impact on confidentiality, integrity, and availability is classified as low. Consequently, no downstream system confidentiality, integrity, or availability consequences are anticipated.
Affected Systems
Intel Transfer Learning Tool versions prior to v0.7 are affected. Any deployment of this product that has not been updated beyond v0.7 may be vulnerable.
Risk and Exploitability
The CVSS score of 6.3 reflects a moderate severity, but the EPSS score is under 1%, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can potentially reach the vulnerable component over the network, but the attack does not require special internal knowledge or user interaction.
OpenCVE Enrichment