Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
Conclusion & alert: CVE-2023-28823 is rated Low Risk (32.8/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-17 | 0.04% | 0.06% | +0.02% |
| 2 | 2023-08-11 | — | 0.04% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.7 | 3.1 | MEDIUM |
|
0.8 | 5.9 | [email protected] |
| 7.3 | 3.1 | HIGH |
|
1.3 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| intel | advisor_for_oneapi | < 2023.1 | cpe:2.3:a:intel:advisor_for_oneapi:*:*:*:*:*:*:*:* |
| intel | cpu_runtime_for_opencl_applications | < 2023.1 | cpe:2.3:a:intel:cpu_runtime_for_opencl_applications:*:*:*:*:*:*:*:* |
| intel | distribution_for_python_programming_language | < 2023.1 | cpe:2.3:a:intel:distribution_for_python_programming_language:*:*:*:*:*:*:*:* |
| intel | dpc\+\+_compatibility_tool | < 2023.1 | cpe:2.3:a:intel:dpc\+\+_compatibility_tool:*:*:*:*:*:*:*:* |
| intel | embree_ray_tracing_kernel_library | < 2023.1 | cpe:2.3:a:intel:embree_ray_tracing_kernel_library:*:*:*:*:*:*:*:* |
| intel | fortran_compiler | < 2023.1 | cpe:2.3:a:intel:fortran_compiler:*:*:*:*:*:*:*:* |
| intel | implicit_spmd_program_compiler | < 1.19.1 | cpe:2.3:a:intel:implicit_spmd_program_compiler:*:*:*:*:*:*:*:* |
| intel | inspector_for_oneapi | < 2023.1 | cpe:2.3:a:intel:inspector_for_oneapi:*:*:*:*:*:*:*:* |
| intel | integrated_performance_primitives | < 2021.8 | cpe:2.3:a:intel:integrated_performance_primitives:*:*:*:*:*:*:*:* |
| intel | ipp_cryptography | < 2021.7.0 | cpe:2.3:a:intel:ipp_cryptography:*:*:*:*:*:*:*:* |
| intel | mpi_library | < 2021.9.0 | cpe:2.3:a:intel:mpi_library:*:*:*:*:*:*:*:* |
| intel | oneapi_base_toolkit | < 2023.1 | cpe:2.3:a:intel:oneapi_base_toolkit:*:*:*:*:*:*:*:* |
| intel | oneapi_data_analytics_library | < 2023.1 | cpe:2.3:a:intel:oneapi_data_analytics_library:*:*:*:*:*:*:*:* |
| intel | oneapi_deep_neural_network_library | < 2023.1 | cpe:2.3:a:intel:oneapi_deep_neural_network_library:*:*:*:*:*:*:*:* |
| intel | oneapi_dpc\+\+\/c\+\+_compiler | < 2023.1 | cpe:2.3:a:intel:oneapi_dpc\+\+\/c\+\+_compiler:*:*:*:*:*:*:*:* |
| intel | oneapi_dpc\+\+_library_\(onedpl\) | < 2022.1 | cpe:2.3:a:intel:oneapi_dpc\+\+_library_\(onedpl\):*:*:*:*:*:*:*:* |
| intel | oneapi_hpc_toolkit | < 2023.1 | cpe:2.3:a:intel:oneapi_hpc_toolkit:*:*:*:*:*:*:*:* |
| intel | oneapi_iot_toolkit | < 2023.1 | cpe:2.3:a:intel:oneapi_iot_toolkit:*:*:*:*:*:*:*:* |
| intel | oneapi_math_kernel_library | < 2023.1 | cpe:2.3:a:intel:oneapi_math_kernel_library:*:*:*:*:*:*:*:* |
| intel | oneapi_rendering_toolkit | < 2023.1 | cpe:2.3:a:intel:oneapi_rendering_toolkit:*:*:*:*:*:*:*:* |
| intel | oneapi_threading_building_blocks | < 2021.9.0 | cpe:2.3:a:intel:oneapi_threading_building_blocks:*:*:*:*:*:*:*:* |
| intel | oneapi_toolkit_and_component_software_installer | < 4.3.1.493 | cpe:2.3:a:intel:oneapi_toolkit_and_component_software_installer:*:*:*:*:*:*:*:* |
| intel | oneapi_video_processing_library | < 2023.1 | cpe:2.3:a:intel:oneapi_video_processing_library:*:*:*:*:*:*:*:* |
| intel | open_image_denoise | < 1.4.3 | cpe:2.3:a:intel:open_image_denoise:*:*:*:*:*:*:*:* |
| intel | open_volume_kernel_library | < 2023.1 | cpe:2.3:a:intel:open_volume_kernel_library:*:*:*:*:*:*:*:* |
| intel | ospray | < 2023.1 | cpe:2.3:a:intel:ospray:*:*:*:*:*:*:*:* |
| intel | ospray_studio | < 2023.1 | cpe:2.3:a:intel:ospray_studio:*:*:*:*:*:*:*:* |
| intel | trace_analyzer_and_collector | < 2021.9.0 | cpe:2.3:a:intel:trace_analyzer_and_collector:*:*:*:*:*:*:*:* |
| intel | vtune_profiler_for_oneapi | < 2023.1 | cpe:2.3:a:intel:vtune_profiler_for_oneapi:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00890.html | Vendor Advisory |