Impact
The flaw originates from incorrect default permissions on some Intel R NPU Driver installers that are run in user mode. An unprivileged software adversary, combined with a high attack complexity, may elevate privileges during installation. The weakness falls under CWE-276 and can compromise confidentiality, integrity and availability of the host system.
Affected Systems
Intel R NPU Driver software installers released before version 32.0.100.4511 are affected. The vulnerability is present in the default installation package and can be triggered on any system that installs a vulnerable release as a user application.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity. No EPSS score was provided, and it is inferred that exploitation may be relatively rare or limited to local contexts. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local, authenticated access with a high attack complexity and active user interaction. Upon exploitation, the attacker could elevate privileges and potentially compromise the confidentiality, integrity and availability of the affected machine.
OpenCVE Enrichment