Impact
The vulnerability is a null pointer dereference in kernel mode within Intel PROSet/Wireless WiFi Software for Windows, classified as CWE‑476. The flaw can cause the system to crash, resulting in a loss of availability while confidentiality and integrity remain unaffected. An attacker who can run unprivileged code on the system—without authentication and with low attack complexity—may trigger the dereference, potentially through adjacent access if configuration checks are circumvented.
Affected Systems
Intel PROSet/Wireless WiFi Software for Windows is affected. No specific version information is provided in the advisory, so all releases that include this kernel driver component may be vulnerable until a fix is released.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability, but the EPSS score of less than 1% suggests that exploitation probabilities are low at present. The vulnerability is not listed in the CISA KEV catalog. An attacker would typically need to deploy malicious code on the machine, exploiting the null pointer dereference in a privileged kernel driver. Because the requirement is low complexity and no user interaction is needed, the risk to endpoints remains moderate, emphasizing the importance of applying any vendor patches as soon as they become available.
OpenCVE Enrichment