Impact
An improper conditions check in the Intel NPU Driver allows an unprivileged, authenticated user to trigger a denial of service. The vulnerability does not affect confidentiality, only reduces integrity slightly while severely impacting availability. A local attacker can cause the driver to fail, leading to system instability or crashes, with no user interaction required.
Affected Systems
All versions of the Intel NPU Driver supported by Intel are impacted. This includes drivers that run in a user‑mode context (Ring 3) on operating systems that provide the driver for accelerator usage.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The attack complexity is low and requires only local access with authenticated user privileges, making it relatively easy for a malicious software process on the host to abuse the flaw. The vulnerability is not listed in CISA’s KEV catalog, further indicating that it is not a known widely used exploit.
OpenCVE Enrichment