Impact
Improper privilege management in Intel PROSet/Wireless WiFi Software for Windows allows a local attacker, even without prior authentication, to obtain higher privileges by interacting with privileged processes that run in Ring 2. The flaw enables an unprivileged user to elevate to a more privileged level, potentially granting control over privileged services or settings. The exploitation can lead to unauthorized operations on the system, with confidentiality and integrity effects rated low, but availability may be severely impacted if an attacker can hijack or disrupt privileged functionality.
Affected Systems
The vulnerability applies to Intel PROSet/Wireless WiFi Software for Windows. No specific version information is included in the advisory, so all current releases of the software could be affected until a patch is applied.
Risk and Exploitability
The CVSS score of 7.1 labels the flaw as high severity, indicating that exploitation would grant significant privileges. The EPSS score of less than 1% suggests that exploitation attempts are currently rare and would likely require complex, local attack techniques. The problem can be abused locally and without user interaction, meaning any user with physical or local access could potentially exploit it. The vulnerability is not listed in the CISA KEV catalog, and no publicly available exploits are documented, but its high severity and local nature make prompt remediation critical.
OpenCVE Enrichment