Impact
The bug is an improper input validation flaw in Intel(R) QAT software drivers for Windows before version 1.13 that allows an attacker to elevate privileges. An unprivileged user application can exploit the flaw within ring 3, potentially gaining higher system privileges. The vulnerability can compromise confidentiality, integrity, and availability at high levels, leading to full loss of those values once exploited.
Affected Systems
This issue affects Intel QAT software drivers for Windows with versions older than 1.13. It applies to all installations using those drivers where the software runs with user‑space privileges and no special internal knowledge is required.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity level, and the EPSS score is not available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Attack requirements are local: an authenticated user with low complexity attacks can trigger the escalation, and no user interaction is needed. Given the high impact and local nature, the risk to affected systems is significant when drivers are not updated.
OpenCVE Enrichment