Junglewise Threat Intelligence

CVE-2026-20908: Intel NPU Driver Windows time-of-check time-of-use race condition

CVE-2026-20908 · Severity: info · CVSS 5.8 · Published 2026-08-11

Technologies: Intel NPU Driver for Windows. Vendors: Intel.

Executive brief

Intel's NPU (Neural Processing Unit) Driver for Windows contains a race condition in its device driver that allows an authenticated local attacker to cause a denial of service. The vulnerability requires high complexity to exploit and specific attack conditions, but could crash or freeze the affected system, disrupting dependent applications and operations.

Technical details

CVE-2026-20908 is a time-of-check time-of-use (TOCTOU) race condition in the Intel NPU Driver for Windows kernel-mode driver component. The vulnerability allows an authenticated local user to trigger a denial of service by exploiting a window between a security check and the subsequent operation on a protected resource. The attack requires high complexity and specific preconditions to execute reliably. An attacker can cause system instability, crashes, or temporary unavailability of NPU functionality. The vulnerability has been patched in version 32.0.100.4723 and later.

Affected products

  • Intel NPU Driver for Windows before 32.0.100.4723

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: patched: Update to version 32.0.100.4723 or later available

References

Related threats