CVE-2026-20772

Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Configurations

Configuration 1 (hide)

cpe:2.3:a:intel:connectivity_performance_suite:*:*:*:*:*:*:*:*

History

21 Jul 2026, 15:45

Type Values Removed Values Added
References () https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01429.html - () https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01429.html - Vendor Advisory, Patch
First Time Intel
Intel connectivity Performance Suite
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.7
CPE cpe:2.3:a:intel:connectivity_performance_suite:*:*:*:*:*:*:*:*

12 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 17:16

Updated : 2026-07-21 15:45


NVD link : CVE-2026-20772

Mitre link : CVE-2026-20772

CVE.ORG link : CVE-2026-20772


JSON object : View

Products Affected

intel

  • connectivity_performance_suite
CWE
CWE-427

Uncontrolled Search Path Element