Impact
Untrusted pointer dereference within the Intel® QuickAssist Adapter 8960 software in Ring 3 can be exploited by a local authenticated user with low complexity to gain privileges above their own. The flaw allows an attacker to acquire full control over the system, potentially resulting in loss of confidentiality, integrity, and availability, as the vulnerability can be triggered without user interaction and without special internal knowledge.
Affected Systems
Intel® QuickAssist Adapter 8960 software versions prior to 1.13 are vulnerable. The impact affects any system running that software and where the exploit may be invoked locally.
Risk and Exploitability
The CVSS score of 8.5 indicates severe risk. With no EPSS score and absence from the CISA KEV catalog, the exact exploit prevalence is unknown. Based on the description, it is inferred that the attack is local, requiring an authenticated user with low complexity and no requirement for network exposure or user interaction, making it a highly actionable risk for systems that rely on the adapter.
OpenCVE Enrichment