logo

Finding a Privilege Escalation in the Intel Trusted…

ID: 554bf8f7-d06b-5be5-ab8e-bb8c0271da88

STIX ID: report--554bf8f7-d06b-5be5-ab8e-bb8c0271da88

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report documents a local privilege escalation vulnerability in Intel Trusted Connect Service Client (Intel Management Engine Components v1822.12.0.1132) where the Windows msiexec repair operation sets permissive ACLs (Everyone: Full Control) on files under C:\ProgramData\Intel\iCLS Client\log. The researcher demonstrates exploiting this by creating a hardlink from a log filename to a service executable, triggering the msiexec ACL change to grant full control to the attacker, overwriting the service binary with a payload, and starting the service to create a new administrator account; Intel addressed the issue in version 1909.12.0.1236.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.