Impact
An improper input validation flaw exists in Intel Neural Compressor software versions prior to 3.7 that allows an authenticated user who is normally unprivileged to elevate their privileges locally. The vulnerability stems from failing to validate certain user-supplied data in Ring 3, enabling a limited privilege escalation. The potential compromise of confidentiality and integrity is considered low, and no additional availability impact beyond the initial privilege gain is expected.
Affected Systems
Intel’s Neural Compressor software, used for accelerating machine learning inference, is affected in all releases before version 3.7. The flaw applies to any installation executed under a local user account, presenting a risk to systems that rely on earlier builds.
Risk and Exploitability
With a CVSS score of 4.8, the flaw is of moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and it requires local access and an authenticated session, yet the attack complexity is low and no special internal knowledge is needed. Overall risk remains low, though mitigations are recommended.
OpenCVE Enrichment