Impact
A null pointer dereference in the device driver of Intel PROSet/Wireless WiFi Software for Windows can be triggered by an unauthenticated network adversary with a low complexity attack, allowing the driver to crash and resulting in a denial of service. The vulnerability does not affect data confidentiality or integrity, but it severely compromises system availability.
Affected Systems
All versions of Intel PROSet/Wireless WiFi Software for Windows that incorporate the vulnerable driver are impacted. Specific build numbers are not provided, so any installation prior to the official fix may be susceptible.
Risk and Exploitability
The CVSS score is 7.1 and the EPSS probability is less than 1 %. The vulnerability is not listed in CISA KEV. Attackers who can send data to the target from a network level, without authentication and without special internal knowledge, can potentially trigger the null pointer dereference. The attack requires no user interaction; an unauthenticated user with a low‑complexity attack could reach the vulnerable driver, possibly via adjacent access when attack requirements are not present. While the probability of exploitation is low, the impact on system availability warrants remediation.
OpenCVE Enrichment