Impact
The vulnerability is a protection mechanism failure in Intel Neural Compressor software versions older than 3.6 that occurs within Ring 3. A local, unprivileged software process can exploit this flaw together with a privileged user session to elevate privileges, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
Deployments of Intel Neural Compressor software prior to version 3.6 on operating systems that support Ring 3 privilege mode are impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of fewer than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors are local; an adversary running an unprivileged process can combine this with a privileged user’s session, perform a low‑complexity attack, and requires only passive user interaction. If exploited, the flaw threatens high confidentiality, integrity, and availability exposures.
OpenCVE Enrichment