CVE-2025-20074
7.8Intel · Connectivity Performance Suite
A local Time-of-check Time-of-use (TOCTOU) race condition in Intel Connectivity Performance Suite installers could allow an authenticated user to escalate privileges.
Executive summary
A race condition vulnerability in Intel Connectivity Performance Suite installers, tracked as CVE-2025-20074, presents a risk of local privilege escalation for authenticated users.
Vulnerability
The flaw is a Time-of-check Time-of-use (TOCTOU) race condition (CWE-367) occurring within the software installer. This vulnerability requires the attacker to have authenticated local access to the system to potentially trigger an escalation of privilege.
Business impact
Successful exploitation of this vulnerability allows a local authenticated user to gain elevated privileges on the target system. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to unauthorized system control, data compromise, or the installation of persistent malicious software.
Remediation
Immediate Action: Update Intel Connectivity Performance Suite to version 40.24.11210 or later immediately to resolve the race condition.
Proactive Monitoring: Monitor system logs for unauthorized installation activities or unexpected changes in user privilege levels during maintenance windows.
Compensating Controls: Restrict local user access to the system and ensure that only authorized accounts have permissions to execute installers or administrative tasks.
Exploitation status
Public Exploit Available: No — exploit_available is false.
Analyst recommendation
While this vulnerability requires local authentication, the potential for privilege escalation necessitates prompt attention. Organizations should prioritize updating all instances of Intel Connectivity Performance Suite to the patched version as part of their routine maintenance cycle to mitigate the risk of local system compromise.