CVE-2025-32038 Details
Description
Uncontrolled search path for some FPGA Support Package for the Intel oneAPI DPC++C++ Compiler software before version 2025.0.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
A privilege escalation vulnerability has been identified in the FPGA Support Package for the Intel oneAPI DPC++/C++ Compiler, prior to version 2025.0.1. This vulnerability arises from an uncontrolled search path, which may allow an unprivileged software adversary with authenticated user status to escalate privileges. The attack, characterized by high complexity, could potentially be executed through local access, requiring active user interaction and without special internal knowledge.
Intel has issued a Product Discontinuation Notice for the FPGA Support Package for the Intel oneAPI DPC++/C++ Compiler. Users are advised to uninstall or discontinue use of this package as soon as possible.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 11, 2025CISA-ADP
Assessed Nov 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01364.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intel FPGA Support Package | All versions |
CPE
Remediation
| |
| Intel oneAPI DPC++/C++ Compiler | < 2025.0.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 11, 2025 | New CVE Received | [email protected] |
Volerion