Executive brief
Intel Extension for TensorFlow is a software library that optimizes TensorFlow machine learning workloads on Intel processors. A protection mechanism failure in versions before 2.15.0.3 allows a privileged local user to escalate their privileges, potentially compromising the confidentiality, integrity, and availability of the affected system. The vulnerability requires passive user interaction and local access, making it a concern primarily for multi-user systems or those where attackers have already obtained some level of system access.
Technical details
This vulnerability is a protection mechanism failure (CWE-693) in Intel Extension for TensorFlow running in Ring 3 (user-mode applications). The root cause involves inadequate privilege isolation within the software. An attacker with elevated privileges (system software adversary) can exploit this via a low-complexity local attack vector requiring passive user interaction to escalate their privilege level. The vulnerability impacts confidentiality, integrity, and availability of the local system. Intel released a patch in version 2.15.0.3 and recommends all users on versions released before November 14, 2025 update immediately.
Affected products
- Intel Extension for TensorFlow before 2.15.0.3
Timeline
- 2026-08-11: disclosed
- 2025-11-14: patched: Version 2.15.0.3 released