Impact
The vulnerability is an improper firmware condition check in the Intel(R) NPU Driver that can be exploited by a local, authenticated user with low attack complexity. The flaw allows an attacker to trigger a denial of service, resulting in high availability impact and low integrity impact; confidentiality is unaffected. The issue stems from CWE‑754, an improper check of conditions or permissions that permits unverified actions to proceed.
Affected Systems
Intel NPU Driver, all versions within Ring 1: Device Drivers. No specific version enumerations are listed, so all driver releases in this family are potentially affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is below 1% and the vulnerability is not listed in CISA's KEV catalog, suggesting a very low likelihood of exploitation at the current time. The attack requires local access, an authenticated user, and no special internal knowledge, with no user interaction needed. Therefore, while the potential impact can be significant for affected systems, real world exploitation is considered unlikely without the necessary local environment.
OpenCVE Enrichment