CVE-2025-20622: Low severity Intel NPU Drivers vulnerability
Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before version 32.0.100.4023 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20622?
CVE-2025-20622 is classified as a medium severity vulnerability due to potential information disclosure.
How do I fix CVE-2025-20622?
To remedy CVE-2025-20622, update the Intel NPU Drivers to version 32.0.100.4023 or later.
What types of systems are affected by CVE-2025-20622?
CVE-2025-20622 affects Intel NPU Drivers for Windows before version 32.0.100.4023.
Who can exploit CVE-2025-20622?
An unprivileged software adversary with an authenticated user account can exploit CVE-2025-20622.
What is the impact of CVE-2025-20622?
CVE-2025-20622 can lead to the unintended disclosure of sensitive information due to memory not being cleared.