Impact
The vulnerability is an out‑of‑bounds read in the Intel NPU Driver that can be triggered by unprivileged local software. Exploiting the flaw may result in a crash of the driver or the associated service, causing an interruption of the system’s normal operation. The weakness, identified as CWE-125, provides no confidentiality gain, introduces a low‑level integrity effect, but delivers a high‑level availability impact as described in the advisory.
Affected Systems
All versions of the Intel(R) NPU Driver are susceptible to the issue. The affected component is the driver code executing in user space (Ring 3). No specific vendor version numbering is provided, so any deployment of the driver remains at risk until a patch is applied.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability sits in the medium range, and the EPSS score of less than 1 % indicates a very low probability of exploitation at the time of this assessment. The flaw is not listed in the CISA KEV catalog, which suggests limited or no known widespread exploitation. The attack requires local access by an authenticated user, low technical skill, and no special internal knowledge; it can be performed without user interaction, making a local denial of service straightforward to achieve once the driver is in play.
OpenCVE Enrichment