Uncontrolled Search Path Vulnerability in Intel Processor Identification Utility
CVE-2025-32001

5.4MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 November 2025

What is CVE-2025-32001?

The Intel Processor Identification Utility contains a vulnerability that allows an attacker to manipulate the search path for executable files. This weakness occurs due to improper handling of application paths before version 8.0.43, potentially enabling an authenticated user to escalate privileges. If exploited, an attacker with local access could execute arbitrary code, posing significant risks to system confidentiality, integrity, and availability. Users are advised to update to the latest version to mitigate these risks.

Affected Version(s)

Intel(R) Processor Identification Utility before version 8.0.43

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32001 : Uncontrolled Search Path Vulnerability in Intel Processor Identification Utility