Impact
Deserialization of untrusted data in Intel Extension for PyTorch prior to version 2.8.0 allows a local attacker to craft payloads that, when processed, can elevate privileges on the host. The vulnerability is able to compromise confidentiality, integrity, or availability at a low level, as the official description notes the impact is limited to low. This weakness falls under Object Deserialization (CWE‑502).
Affected Systems
Any installation of Intel Extension for PyTorch older than version 2.8.0 that handles user‑supplied serialized data is affected. The issue does not apply to later releases, and no specific sub‑products or operating systems are singled out beyond the general Intel Extension for PyTorch component.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, yet the EPSS score is less than 1 %, signalling very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local, unauthenticated attacker who can run the software and supply a malicious serialized object, and it needs active user interaction – the likely attack vector is therefore local user‑initiated exploitation. Given these constraints the overall risk to most environments remains low, but the possibility of privilege escalation warrants attention.
OpenCVE Enrichment