CVE-2024-23907: Intel High Level Synthesis Compiler

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected products

  • Intel High Level Synthesis Compiler: before 23.4 (fixed in 23.4)
  • Intel Oneapi Dpc++/c++ Compiler: before 2024.1 (fixed in 2024.1)
  • Intel Quartus Prime: before 23.4 (fixed in 23.4)

Published 2024-08-14. Last modified 2026-06-17.