Impact
The flaw is a failure in the protection mechanism for Intel AI Reference Models before version 3.4.1 that allows a user‑level application to escape Ring 3. The result is an elevation of privilege that can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Intel AI Reference Models with firmware versions earlier than 3.4.1. The vulnerability applies exclusively to the ring 3 environment accessed by user applications.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of < 1% shows a very low probability of exploitation in the wild. The flaw can be triggered by an unprivileged process in a position to run alongside a privileged user, with a low‑complexity attack and without the need for special internal knowledge. Because the attack requires only local access and passive user interaction, a local attacker could potentially leverage the weakness to gain root‑level privileges. The vulnerability is not yet listed in the CISA KEV catalog, but the high impact on confidentiality, integrity, and availability warrants prompt remediation.
OpenCVE Enrichment