Information Disclosure Vulnerability in Intel NPU Drivers for Windows
CVE-2025-20622

2LOW

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 November 2025

What is CVE-2025-20622?

Sensitive information may be improperly managed by certain Intel NPU Drivers for Windows before version 32.0.100.4023, allowing unprivileged software adversaries to potentially exploit this weakness. This vulnerability can lead to unauthorized access and exposure of confidential data, requiring only authenticated user access and minimal complexity to exploit. The incident can occur locally without the need for special internal knowledge or user interaction, making it a significant concern for users relying on these drivers for optimal system performance.

Affected Version(s)

Intel(R) NPU Drivers for Windows before version 32.0.100.4023

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.