---
id: CVE-2026-32791
title: >-
  Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R)
  PCM) before version tag 202604 within Ring 3: User Applications may allow an
  escalation of privilege
summary: >-
  Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R)
  PCM) before version tag 202604 within Ring 3: User Applications may allow an
  escalation of privilege. Unprivileged software adversary with an authenticated
  use…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-426
  - CWE-426
vendor: intel
product: performance_counter_monitor
affected:
  - performance_counter_monitor < 2026-04-06
patched:
  - performance_counter_monitor 2026-04-06
published: '2026-08-11'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T15:06:36.343'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-32791'
references:
  - url: >-
      https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01488.html
    label: secure@intel.com
tags:
  - nvd
epss: 0.00121
epssPercentile: 0.01716
ingestedAt: '2026-10-02T15:21:27.976Z'
---

## Overview

Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

## Affected

- `performance_counter_monitor < 2026-04-06`

## Remediation

Upgrade past the affected range:

- `performance_counter_monitor 2026-04-06`
