Intel ITT API Uncontrolled Search Path Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability exists in the Intel Instrumentation and Tracing Technology API (ITT API) software prior to version 3.25.4, which may allow an escalation of privilege. This issue arises from an uncontrolled search path within user applications, potentially enabling an unprivileged, authenticated user to execute a complex attack that escalates privileges. The vulnerability requires local access, active user interaction, and does not demand special internal knowledge. It could significantly impact the system's confidentiality, integrity, and availability.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to gain elevated rights or access within the system.

Remediation

Users are advised to update the ITT API software to version 3.25.4 or later. The latest version can be downloaded from the Intel ITT API GitHub releases page. Additionally, users of Intel oneAPI Toolkits, Intel HPC Toolkit, or Intel VTune Profiler should update to the latest versions available through the Intel oneAPI Toolkit download page.

Added: Nov 11, 2025, 6:16 PM
Updated: Nov 11, 2025, 6:16 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
2.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.