Impact
The Intel(R) NPU Driver contains an improper buffer restriction flaw that enables local unprivileged users, who possess an authenticated session, to trigger a denial of service. Exploitation requires no special internal knowledge or user interaction, and involves a low complexity attack. The flaw can crash the driver or the system, causing high availability impact while leaving confidentiality unaffected and integrity low if the driver state is corrupted.
Affected Systems
The flaw is present in all versions of the Intel(R) NPU Driver operating in Ring 3. Intel’s official advisory lists the vulnerable driver as the affected product, with no specific version range disclosed, meaning that any user of the driver in a normal privilege context may be impacted.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate to high risk, but the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is local and requires authentication; an attacker could cause repeated crashes of the driver or the host operating system, leading to service outages.
OpenCVE Enrichment