Impact
A driver in Intel PROSet/Wireless WiFi Software for Windows can reveal sensitive data and allow an unprivileged local user to gain elevated privileges, potentially enabling local code execution. The flaw exploitable without authentication and requires low effort from an attacker, meaning it can compromise confidentiality and elevate privileges with relative ease.
Affected Systems
Intel PROSet/Wireless WiFi Software for Windows is affected. No version details are presently supplied, so all current builds should be evaluated.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local access, can operate with minimal complexity, and no user interaction is necessary. If exploited, an attacker could read privileged data and execute additional code, leading to a high confidentiality impact for the system.
OpenCVE Enrichment