Executive brief
Intel Neural Compressor is software used for optimizing machine learning models. A vulnerability in versions before 3.7 allows an authenticated local user to escalate their privileges on the system without requiring any special knowledge or user interaction, potentially compromising system security and data integrity.
Technical details
A improper input validation vulnerability exists in Intel Neural Compressor before version 3.7 that allows privilege escalation. The flaw is present in Ring 3 user-mode applications and can be exploited by an authenticated local adversary with low attack complexity and no special preconditions. The vulnerability requires no user interaction and has low impact on system confidentiality, integrity, and availability. Intel recommends updating to version 3.7 or later, with patches available on GitHub.
Affected products
- Intel Neural Compressor before 3.7
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Version 3.7 released