Junglewise Threat Intelligence

CVE-2026-20772: Intel Connectivity Performance Suite uncontrolled search path in installers

CVE-2026-20772 · Severity: medium · CVSS 6.7 · Published 2026-05-12

Vendors: Intel.

Executive brief

A vulnerability in the installation software for Intel Connectivity Performance Suite could allow a local attacker to gain elevated system privileges. This occurs when the installer incorrectly searches for files, potentially loading malicious code provided by an attacker instead of legitimate components. To exploit this, an attacker would need local access to the machine and would require a user to perform specific actions during the installation process.

Technical details

An uncontrolled search path (CWE-427) vulnerability exists in the Intel Connectivity Performance Suite software installers within Ring 3 (User Applications). The flaw allows an unprivileged local attacker to achieve escalation of privilege by placing a malicious file in a directory searched by the installer. Exploitation is considered high complexity as it requires specific timing or environmental conditions and active user interaction. Successful exploitation grants the attacker high confidentiality, integrity, and availability impacts on the local system. Intel has released version 50.25.1121.193 to mitigate this issue.

Affected products

  • Intel Connectivity Performance Suite software installers before 50.25.1121.193

Timeline

  • 2026-05-12: disclosed: Initial release of Intel advisory INTEL-SA-01429
  • 2026-05-12: patched: Update to version 50.25.1121.193 or later recommended

References