Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
Conclusion & alert: CVE-2023-22355 is rated Low Risk (30.8/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.21%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.07% | 0.21% | +0.14% |
| 2 | 2026-05-21 | 0.15% | 0.07% | -0.09% |
| 3 | 2026-05-11 | — | 0.15% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.7 | 3.1 | MEDIUM |
|
0.8 | 5.9 | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| intel | advisor | < 2023.0 | cpe:2.3:a:intel:advisor:*:*:*:*:*:oneapi:*:* |
| intel | cpu_runtime | < 2023.0 | cpe:2.3:a:intel:cpu_runtime:*:*:*:*:*:opencl:*:* |
| intel | distribution_for_python | < 2023.0 | cpe:2.3:a:intel:distribution_for_python:*:*:*:*:*:*:*:* |
| intel | dpc\+\+_compatibility_tool | < 2023.0 | cpe:2.3:a:intel:dpc\+\+_compatibility_tool:*:*:*:*:*:*:*:* |
| intel | embree_ray_tracing_kernel_library | < 2023.0 | cpe:2.3:a:intel:embree_ray_tracing_kernel_library:*:*:*:*:*:*:*:* |
| intel | fortran_compiler | < 2023.0 | cpe:2.3:a:intel:fortran_compiler:*:*:*:*:*:*:*:* |
| intel | implicit_spmd_program_compiler | < 1.18.1 | cpe:2.3:a:intel:implicit_spmd_program_compiler:*:*:*:*:*:*:*:* |
| intel | inspector | < 2023.0 | cpe:2.3:a:intel:inspector:*:*:*:*:*:oneapi:*:* |
| intel | integrated_performance_primitives | < 2021.7 | cpe:2.3:a:intel:integrated_performance_primitives:*:*:*:*:*:*:*:* |
| intel | integrated_performance_primitives_cryptography | < 2021.6.3 | cpe:2.3:a:intel:integrated_performance_primitives_cryptography:*:*:*:*:*:*:*:* |
| intel | mpi_library | < 2021.8 | cpe:2.3:a:intel:mpi_library:*:*:*:*:*:*:*:* |
| intel | oneapi_base_toolkit | < 2023.0 | cpe:2.3:a:intel:oneapi_base_toolkit:*:*:*:*:*:*:*:* |
| intel | oneapi_data_analytics_library | < 2023.0 | cpe:2.3:a:intel:oneapi_data_analytics_library:*:*:*:*:*:*:*:* |
| intel | oneapi_deep_neural_network_library | < 2023.0 | cpe:2.3:a:intel:oneapi_deep_neural_network_library:*:*:*:*:*:*:*:* |
| intel | oneapi_dpc\+\+\/c\+\+_compiler | < 2023.0 | cpe:2.3:a:intel:oneapi_dpc\+\+\/c\+\+_compiler:*:*:*:*:*:*:*:* |
| intel | oneapi_dpc\+\+_library | < 2022.0 | cpe:2.3:a:intel:oneapi_dpc\+\+_library:*:*:*:*:*:*:*:* |
| intel | oneapi_hpc_toolkit | < 2023.0.0 | cpe:2.3:a:intel:oneapi_hpc_toolkit:*:*:*:*:*:*:*:* |
| intel | oneapi_hpc_toolkit | 2023.0.0 | cpe:2.3:a:intel:oneapi_hpc_toolkit:2023.0.0:*:*:*:*:*:*:* |
| intel | oneapi_iot_toolkit | < 2023.0 | cpe:2.3:a:intel:oneapi_iot_toolkit:*:*:*:*:*:*:*:* |
| intel | oneapi_math_kernel_library | < 2023.0 | cpe:2.3:a:intel:oneapi_math_kernel_library:*:*:*:*:*:*:*:* |
| intel | oneapi_rendering_toolkit | < 2023.0 | cpe:2.3:a:intel:oneapi_rendering_toolkit:*:*:*:*:*:*:*:* |
| intel | oneapi_threading_building_blocks | < 2021.8 | cpe:2.3:a:intel:oneapi_threading_building_blocks:*:*:*:*:*:*:*:* |
| intel | oneapi_toolkit_and_component_software_installers | < 4.3.0.251 | cpe:2.3:a:intel:oneapi_toolkit_and_component_software_installers:*:*:*:*:*:*:*:* |
| intel | oneapi_video_processing_library | < 2023.0 | cpe:2.3:a:intel:oneapi_video_processing_library:*:*:*:*:*:*:*:* |
| intel | open_image_denoise | < 1.4.3 | cpe:2.3:a:intel:open_image_denoise:*:*:*:*:*:*:*:* |
| intel | open_volume_kernel_library | < 2023.0 | cpe:2.3:a:intel:open_volume_kernel_library:*:*:*:*:*:*:*:* |
| intel | ospray | < 2023.0 | cpe:2.3:a:intel:ospray:*:*:*:*:*:*:*:* |
| intel | ospray_studio | < 2023.0 | cpe:2.3:a:intel:ospray_studio:*:*:*:*:*:*:*:* |
| intel | trace_analyzer_and_collector | < 2021.8.0 | cpe:2.3:a:intel:trace_analyzer_and_collector:*:*:*:*:*:*:*:* |
| intel | vtune_profiler | < 2023.0 | cpe:2.3:a:intel:vtune_profiler:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00819.html | Vendor Advisory |