CVE-2026-32791

Description

A flaw was found in Intel Performance Counter Monitor (Intel PCM). An unprivileged, authenticated local attacker could exploit an untrusted search path vulnerability. This could lead to an escalation of privilege, allowing the attacker to gain higher access rights. The vulnerability has a high impact on the confidentiality, integrity, and availability of the affected system.

Statement

An untrusted search path vulnerability exists in Intel Performance Counter Monitor (PCM) before version 202604 in Ring 3 user application execution contexts. Due to improper path resolution, an authenticated local attacker with low privileges can place a malicious shared library or executable binary in a directory searched by PCM applications. When a privileged user or service executes PCM, it loads the attacker's binary, leading to local privilege escalation and full compromise of system confidentiality, integrity, and availability.

Mitigation

To mitigate this issue, restrict write permissions on directories along the system execution path to trusted administrative accounts, or run Intel PCM binary tools exclusively from secure, root-owned installation paths.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.7N/AN/A
Attack VectorLocalN/AN/A
Attack ComplexityHighN/AN/A
Privileges RequiredLowN/AN/A
User InteractionRequiredN/AN/A
ScopeUnchangedN/AN/A
ConfidentialityHighN/AN/A
Integrity ImpactHighN/AN/A
Availability ImpactHighN/AN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability,Access Control

Technical Impact: Gain Privileges or Assume Identity; Execute Unauthorized Code or Commands

There is the potential for arbitrary code execution with privileges of the vulnerable program.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

The program could be redirected to the wrong files, potentially triggering a crash or hang when the targeted file is too large or does not have the expected format.

Confidentiality

Technical Impact: Read Files or Directories

The program could send the output of unauthorized files to the attacker.

Frequently Asked Questions

Want to get errata notifications? Sign up here.