---
id: CVE-2023-27506
aliases:
  - GHSA-m2f8-v8q4-3m59
  - PYSEC-2026-1465
title: >-
  Authenticated Local Privilege Escalation vulnerability in Intel Optimization
  for Tensorflow
summary: >-
  Authenticated Local Privilege Escalation vulnerability in Intel Optimization
  for Tensorflow
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L'
vendor: intel-tensorflow
product: intel-tensorflow
ecosystem: pip
affected:
  - intel-tensorflow < 2.12
  - tensorflow-intel < 2.12
  - intel-tensorflow-avx512 < 2.12
patched:
  - intel-tensorflow 2.12
  - tensorflow-intel 2.12
  - intel-tensorflow-avx512 2.12
published: '2023-08-11'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-m2f8-v8q4-3m59'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-27506'
  - url: >-
      http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00840.html
tags:
  - osv
  - pip
epss: 0.0016
epssPercentile: 0.04497
ingestedAt: '2026-07-08T18:25:50.916Z'
---

## Overview

Improper buffer restrictions in the Intel(R) Optimization for Tensorflow software before version 2.12 may allow an authenticated user to potentially enable escalation of privilege via local access.

## Affected packages

- `intel-tensorflow < 2.12`
- `tensorflow-intel < 2.12`
- `intel-tensorflow-avx512 < 2.12`

## Remediation

Upgrade to a patched release:

- `intel-tensorflow 2.12`
- `tensorflow-intel 2.12`
- `intel-tensorflow-avx512 2.12`
