Impact
The Intel(R) LLM Library for PyTorch contains a protection mechanism failure that allows unprivileged software to elevate its privileges when running in Ring 3. An adversary using a low‑complexity attack can exploit this flaw through local access; the description indicates the attack does not require special internal knowledge and only passive user interaction is needed. If successful, the attacker could gain higher privilege level, compromising confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects applications that rely on the Intel LLM Library for PyTorch. Specific vendor and product details are limited, but any system running a version of this library that is not yet patched is susceptible. The description does not provide explicit version ranges, so all deployments of the library remain potentially impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity risk. The EPSS score is below 1 %, suggesting a low probability of exploitation as of the analysis time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and a low‑complexity attack; it is likely that attackers would target systems where the library is used without additional hardening.
OpenCVE Enrichment