Executive brief
Intel AI Reference Models is a software framework for running artificial intelligence models. A protection mechanism failure allows unprivileged users to escalate privileges and gain full control over system data and operations. The vulnerability requires local access and interaction with a privileged user, but once exploited, an attacker can read, modify, or delete sensitive information and disrupt services.
Technical details
A protection mechanism failure exists in Intel AI Reference Models software before version v3.4.1, specifically within Ring 3 (user-mode applications). The vulnerability allows an unprivileged local adversary with passive user interaction from a privileged account to escalate privileges via low-complexity exploitation. The attack vector is local, requires high privileges to be present, and passive user interaction. When exploited, the vulnerability can compromise confidentiality, integrity, and availability of the affected system. Intel recommends updating to version v3.4.1 or later, which is available on GitHub.
Affected products
- Intel AI Reference Models before v3.4.1
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Version v3.4.1 available on GitHub