Executive brief
A vulnerability in the installation software for Intel Connectivity Performance Suite could allow a local attacker to gain elevated system privileges. This occurs when the installer incorrectly searches for files, potentially loading malicious code provided by an attacker instead of legitimate components. To exploit this, an attacker would need local access to the machine and would require a user to perform specific actions during the installation process.
Technical details
An uncontrolled search path (CWE-427) vulnerability exists in the Intel Connectivity Performance Suite software installers within Ring 3 (User Applications). The flaw allows an unprivileged local attacker to achieve escalation of privilege by placing a malicious file in a directory searched by the installer. Exploitation is considered high complexity as it requires specific timing or environmental conditions and active user interaction. Successful exploitation grants the attacker high confidentiality, integrity, and availability impacts on the local system. Intel has released version 50.25.1121.193 to mitigate this issue.
Affected products
- Intel Connectivity Performance Suite software installers before 50.25.1121.193
Timeline
- 2026-05-12: disclosed: Initial release of Intel advisory INTEL-SA-01429
- 2026-05-12: patched: Update to version 50.25.1121.193 or later recommended