Executive brief
Intel's LLM Library for PyTorch is a software library used to optimize machine learning models on Intel hardware. A protection mechanism failure in this library allows a local attacker to escalate privileges on an affected system. Intel has discontinued the product and recommends users uninstall it immediately, as no patches will be provided.
Technical details
The vulnerability is a protection mechanism failure affecting Ring 3 user-mode applications in Intel LLM Library for PyTorch. It requires local access, involves passive user interaction, and mandates high privilege context (PR:H per CVSS 4.0). An unprivileged adversary can exploit this with low attack complexity to achieve privilege escalation, potentially compromising system confidentiality, integrity, and availability. No patches are available; Intel has issued a Product Discontinuation Notice indicating the software will receive no further updates.
Affected products
- Intel LLM Library for PyTorch all versions
Timeline
- 2026-08-11: disclosed