CVE-2026-20908
Awaiting Analysis Awaiting Analysis - Queue

Time-of-Check Time-of-Use Race Condition in Intel NPU Driver for Windows

Vulnerability report for CVE-2026-20908, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Intel Corporation

Description

Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
intel npu_driver *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a time-of-check time-of-use race condition in the Intel NPU Driver for Windows. It allows an unprivileged attacker with authenticated access to cause a denial of service through a high-complexity local attack without special internal knowledge or user interaction.

Detection Guidance

This vulnerability is a race condition in the Intel NPU Driver for Windows. Detection requires checking for vulnerable driver versions and monitoring for unusual system behavior. No specific commands are provided in the context to directly detect this issue.

Impact Analysis

The vulnerability may lead to system unavailability due to a denial of service. It has high impact on availability but low impact on integrity and no impact on confidentiality. The attack requires local access and authenticated user privileges.

Compliance Impact

This vulnerability primarily impacts system availability due to a denial of service risk, which may indirectly affect compliance with standards like GDPR or HIPAA by disrupting data processing or access. However, the provided context does not specify direct impacts on confidentiality or integrity beyond low integrity and high availability risks.

Mitigation Strategies

Update the Intel NPU Driver for Windows to the latest version provided by Intel to address the race condition vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20908. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart