Impact
The vulnerability is a protection‑mechanism failure in Intel Extension for TensorFlow software before version 2.15.0.3 that allows a user application to gain higher privileges. An attacker can use the flaw to lift privileges within the system, potentially compromising the confidentiality and integrity of the affected system. The impact is listed as high for confidentiality, integrity, and availability, but the realistic consequence for the overall system is none, indicating that the flaw primarily affects the local user context.
Affected Systems
Intel Extension for TensorFlow software versions prior to 2.15.0.3 on any platform that uses the TensorFlow extension. The vulnerability applies to all installations that run the unpatched version within a user’s application space.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% reflects a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog, further lowering its exposure risk. The attack is local and requires a system‑software adversary to have privileged user access and a low‑complexity attack, combined with passive user interaction. If the conditions are met, an attacker can elevate privileges and gain unauthorized control over the system, but the overall risk remains moderate due to the low likelihood of exploitation.
OpenCVE Enrichment