Description
Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted search path exists in Battery Life Diagnostic Tool software before version 2.9.0, allowing a malicious executable placed in a user‑writable directory to be selected and run under the tool’s process. Because the tool operates with ordinary user privileges, this flaw can be used by an authenticated local attacker to gain elevated rights, potentially compromising the confidentiality, integrity and availability of the system as high‑level effects are reported. The vulnerability requires local access, an authenticated user, a high‑complexity attack, and passive user interaction for exploitation.

Affected Systems

All installations of Battery Life Diagnostic Tool software with a version earlier than 2.9.0 are affected. The vendor is unspecified in the advisory, and only the major version threshold is identified.

Risk and Exploitability

The CVSS score is 5.4 and the EPSS score is less than 1%, indicating moderate base severity but a very low probability of real‑world exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access and a user with authentication, and must be performed without special internal knowledge. The exploitation path therefore runs from a local user context to a higher privilege state via the tool’s search mechanism.

Generated by OpenCVE AI on August 13, 2026 at 02:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Battery Life Diagnostic Tool to version 2.9.0 or later to remove the untrusted search path.
  • If upgrade is delayed, reconfigure the tool’s search directories to exclude any user‑writeable locations or enforce strict permissions so that only trusted system directories are considered.
  • Run the tool with the narrowest set of rights necessary and monitor for execution of unexpected binaries in its directories.

Generated by OpenCVE AI on August 13, 2026 at 02:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel battery Life Diagnostic Tool
Vendors & Products Intel
Intel battery Life Diagnostic Tool

Thu, 13 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Untrusted Search Path in Battery Life Diagnostic Tool Allows Local Privilege Escalation

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-426
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Intel Battery Life Diagnostic Tool
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:37:36.169Z

Reserved: 2025-12-19T04:00:14.803Z

Link: CVE-2026-20799

cve-icon Vulnrichment

Updated: 2026-08-12T15:37:22.768Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:53.573

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-20799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses