CVE-2025-20108 Details
Description
Uncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
A vulnerability allowing unauthorized privilege escalation has been identified in certain Intel Network Adapter Driver installers for Windows 11, prior to version 29.4. This vulnerability arises from an uncontrolled search path element, which could be exploited by an authenticated user with local access.
Users are advised to update the Intel Network Adapter Driver for Microsoft Windows 11 to version 29.4 or later. The update is available for download from the Intel Download Center. Additionally, users should update the Administrative Tools for Intel Network Adapters to version 29.4 or later, with the update also available from the Intel Download Center. For those using the Intel Ethernet Adapter Complete Driver Pack, version 29.4 or later should be installed, with the update available from the Intel Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2025CISA-ADP
Assessed May 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01293.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intel Network Adapter Driver | All versions |
CPE
Remediation
| |
| Intel Administrative Tools | < 29.4 |
CPE
Remediation
| |
| Intel Ethernet Adapter Complete Driver Pack | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2025 | New CVE Received | [email protected] |
Volerion