Impact
An improper access control flaw in Intel’s PROSet/Wireless WiFi Software for Windows drivers allows local code execution by non‑privileged software. The defect is a classic privilege escalation issue (CWE‑284) that can lead to execution of arbitrary code with elevated privileges, potentially compromising system integrity and availability.
Affected Systems
The affected product is Intel PROSet/Wireless WiFi Software for Windows. No specific version numbers are listed in the advisory, so any installation of the driver that includes the vulnerable code is considered at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4, indicating high severity, and an EPSS score of less than 1%, suggesting a low probability of current exploitation. It is not listed in the CISA KEV catalog. The attack requires local access, low complexity, and does not need user interaction or special internal knowledge. An attacker who can run unprivileged code on the target system could exploit the flaw to gain elevated privileges, with high impact on availability and potential for subsequent confidentiality and integrity damage.
OpenCVE Enrichment