Intel IPP Crypto Incomplete Cleanup Local Privilege Disclosure (v2021.6)
CVE-2022-40974 Published on May 10, 2023
Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a privileged user to potentially enable information disclosure via local access.
Vulnerability Analysis
CVE-2022-40974 is exploitable with local system access, requires user interaction and user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an Insufficient Cleanup Vulnerability?
The software does not properly "clean up" and remove temporary or supporting resources after they have been used.
CVE-2022-40974 has been classified to as an Insufficient Cleanup vulnerability or weakness.
Products Associated with CVE-2022-40974
Want to know whenever a new CVE is published for Intel Integrated Performance Primitives Cryptography? stack.watch will email you.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.