Skip to content
Weekly Signal
Live intelligence Updated 21 Aug 2026 · 22:12 UTC

Intel · Connectivity Performance Suite

CVE-2026-20772

Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User App...

Recommended action

Handle this through the normal risk-based patching cycle while monitoring for change. Intel Security patch Intel Sa 01429

View response plan
CVSS5.4
EPSS0.1%
KEVNo
ExploitationNone
RemediationExplicit patch identified ↓

Assessment

Why it matters

EPSS is 0.1%; technical severity is CVSS 5.4.

Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

Who should care

  • Teams operating Connectivity Performance Suite
  • Vulnerability and exposure management teams
  • Security operations teams monitoring exploitation activity

Response plan

What I would do

  1. Confirm whether Connectivity Performance Suite is present in the environment.
  2. Identify affected versions and establish whether vulnerable services are exposed or reachable.
  3. Intel Security patch Intel Sa 01429
  4. Review relevant security telemetry for evidence of attempted or successful exploitation.
  5. Document the remediation decision and track it to verified completion.

Treatment intelligence

Remediation intelligence

Not yet verified

Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.

Verification noteAutomated link verification has not completed for this guidance yet.

Technical details

CVSS vector
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-427
Affected versions
Intel Connectivity Performance Suite (End Excluding 50.25.1121.193)
Fixed versions
Intel Connectivity Performance Suite (Fixed from 50.25.1121.193)
Published
12 May 2026
Attack vector
Local
Privileges required
Low
User interaction
Active

Signal timeline

  1. CVE published
  2. Latest EPSS score: 0.1%
  3. Signal calculated at 9
Live public intelligence This assessment combines public-source evidence. Validate the affected product, version and exposure against your own environment before making a risk decision.