PT-2024-8804 · Intel · Intel Neural Compressor

CVE-2024-36284

·

Published

2024-11-12

·

Updated

2024-11-15

CVSS v3.1

5.5

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Intel Neural Compressor versions prior to v3.0
Description: The issue is related to insufficient input validation in the Intel Neural Compressor library, which can be exploited by a remote attacker to potentially escalate privileges. This can be achieved by an authenticated user via adjacent access.
Recommendations: For versions prior to v3.0, update to version v3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Intel Neural Compressor software to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10436
CVE-2024-36284

Affected Products

Intel Neural Compressor