Uncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE ID: CVE-2024-24852
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.4
CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vendor: n/a
Product: Intel(R) Ethernet Adapter Complete Driver Pack
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.94% (scored less or equal to compared to others)
EPSS Date: 2025-03-13 (when was this score calculated)