Uncontrolled Search Path Vulnerability in Intel Processor Identification Utility
CVE-2025-32001
5.4MEDIUM
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 11 November 2025
What is CVE-2025-32001?
The Intel Processor Identification Utility contains a vulnerability that allows an attacker to manipulate the search path for executable files. This weakness occurs due to improper handling of application paths before version 8.0.43, potentially enabling an authenticated user to escalate privileges. If exploited, an attacker with local access could execute arbitrary code, posing significant risks to system confidentiality, integrity, and availability. Users are advised to update to the latest version to mitigate these risks.
Affected Version(s)
Intel(R) Processor Identification Utility before version 8.0.43
References
CVSS V4
Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved