Description
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An untrusted search path in Intel Performance Counter Monitor (PCM) allows user-mode programs to load an arbitrary executable before the intended system binary, enabling an attacker to gain higher privileges. The flaw is classified as CWE-426 and could compromise confidentiality, integrity, and availability at a high level. The attack requires an authenticated local user and is considered high complexity, with no special internal knowledge beyond accessing the affected system.

Affected Systems

The vulnerability affects Intel PCM releases prior to the 202604 tag. Systems running any earlier version of the Intel Performance Counter Monitor are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score of <1% suggests a low probability of successful exploitation. The flaw is not listed in the CISA KEV catalog, reinforcing its lower exploitation likelihood. Exploitation requires local access and active user interaction, so it is not remotely exploitable without additional pre‑conditions.

Generated by OpenCVE AI on August 12, 2026 at 21:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Intel PCM to version 202604 or later to remove the untrusted search path flaw.
  • Configure the system environment to ensure that the PATH variable does not include untrusted directories that could be searched before the legitimate PCM executable.
  • Limit the execution of PCM to the authenticated user context and monitor for any anomalous file loads in the system logs.

Generated by OpenCVE AI on August 12, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel intel Performance Counter Monitor
Vendors & Products Intel
Intel intel Performance Counter Monitor

Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Untrusted Search Path in Intel Performance Counter Monitor

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Weaknesses CWE-426
References
Metrics cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Intel Intel Performance Counter Monitor
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T14:33:06.872Z

Reserved: 2026-03-20T03:00:17.043Z

Link: CVE-2026-32791

cve-icon Vulnrichment

Updated: 2026-08-12T14:32:59.913Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:57.693

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-32791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:40:04Z

Weaknesses