Impact
Intel® PROSet/Wireless WiFi Software contains an out‑of‑bounds read within a ring‑2 device driver. The flaw enables a network adversary to gain elevated privileges with an unauthenticated connection, employing a low‑complexity attack that does not require user interaction. The read could expose process memory, leading to a modest breach of confidentiality and integrity, but the larger threat is the potential to disrupt services, resulting in high availability impact.
Affected Systems
The vulnerability affects the Intel® PROSet/Wireless WiFi Software driver stack. No specific product versions are listed, so all installations of this driver must be treated as potentially vulnerable until an update is applied.
Risk and Exploitability
The CVSS score of 7.2 combined with an EPSS score of less than 1% indicates moderate overall risk. The flaw is exposed over the network from unauthenticated hosts and can be triggered by adjacent access without special internal knowledge. Although the vulnerability is not listed in CISA KEV, the high availability impact warrants vigilance and prompt mitigation.
OpenCVE Enrichment