Junglewise Threat Intelligence

CVE-2026-20755: Intel LLM Scaler privilege escalation in Ring 3

CVE-2026-20755 · Severity: info · CVSS 5.4 · Published 2026-08-11

Vendors: Intel.

Executive brief

Intel's LLM Scaler software contains a protection mechanism failure that allows unprivileged users to escalate their privileges on a local system. An attacker with limited system access and user interaction could potentially gain elevated permissions, compromising the confidentiality, integrity, and availability of affected systems running the vulnerable software.

Technical details

This is a protection mechanism failure in Intel LLM Scaler software affecting Ring 3 (user applications) that enables privilege escalation. The vulnerability requires local access, an unprivileged software adversary, a privileged user present, and passive user interaction, with low attack complexity. An attacker can achieve escalation of privilege resulting in high impact to confidentiality, integrity, and availability of the vulnerable system. Intel has released software updates (version 1.0 or later) available at https://github.com/intel/llm-scaler/releases to mitigate this issue.

Affected products

  • Intel LLM Scaler 1.0 downloaded before September 11, 2025

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Updates available at https://github.com/intel/llm-scaler/releases

References