Junglewise Threat Intelligence

CVE-2026-20718: Intel NPU Driver privilege escalation in Windows installer

CVE-2026-20718 · Severity: info · CVSS 5.4 · Published 2026-05-12

Technologies: Intel NPU Driver for Windows. Vendors: Intel.

Executive brief

A vulnerability in the Intel NPU Driver for Windows could allow a local user to gain elevated privileges on a system. The issue stems from incorrect file or folder permissions set by the software installer. If exploited, an attacker could gain full control over the affected system, potentially leading to the theft of sensitive data or the disruption of operations.

Technical details

A privilege escalation vulnerability (CWE-276) exists in the Intel NPU Driver for Windows software installer before version 32.0.100.4511. The flaw is caused by incorrect default permissions assigned to components within Ring 3 (User Applications). An authenticated, unprivileged local attacker could exploit this by performing a high-complexity attack that requires active user interaction. Successful exploitation allows the attacker to escalate their privileges to a higher level, impacting the confidentiality, integrity, and availability of the system. Intel has released version 32.0.100.4511 to address this issue.

Affected products

  • Intel NPU Driver for Windows before 32.0.100.4511

Timeline

  • 2026-05-12: advisory: Intel released advisory INTEL-SA-01424
  • 2026-05-12: disclosed: CVE-2026-20718 published

References

Related threats