Input validation error in Intel VTune Profiler and Intel oneAPI Base Toolkit - CVE-2025-20056
Published: November 24, 2025
Vulnerability identifier: #VU118698
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20056
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A local user can pass specially crafted input to the application and enable data manipulation.
Affected software
Intel VTune Profiler
Intel oneAPI Base Toolkit
Intel oneAPI Base Toolkit
How to mitigate CVE-2025-20056
Install updates from vendor's website.
Intel VTune Profiler - update to 2025.1
Intel oneAPI Base Toolkit - update to 2025.1
Intel oneAPI Base Toolkit - update to 2025.1