CVE-2025-31931 Details
Description
Uncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
A vulnerability exists in the Intel Instrumentation and Tracing Technology API (ITT API) software prior to version 3.25.4, which may allow an escalation of privilege. This issue arises from an uncontrolled search path within user applications, potentially enabling an unprivileged, authenticated user to execute a complex attack that escalates privileges. The vulnerability requires local access, active user interaction, and does not demand special internal knowledge. It could significantly impact the system's confidentiality, integrity, and availability.
Users are advised to update the ITT API software to version 3.25.4 or later. The latest version can be downloaded from the Intel ITT API GitHub releases page. Additionally, users of Intel oneAPI Toolkits, Intel HPC Toolkit, or Intel VTune Profiler should update to the latest versions available through the Intel oneAPI Toolkit download page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 11, 2025CISA-ADP
Assessed Nov 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01337.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intel Instrumentation and Tracing Technology API | All versions |
CPE
Remediation
| |
| Intel oneAPI Base Toolkit | All versions |
CPE
Remediation
| |
| Intel HPC Toolkit | All versions |
CPE
Remediation
| |
| Intel VTune Profiler | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 11, 2025 | New CVE Received | [email protected] |
Volerion