Impact
The vulnerability in Intel PROSet/Wireless WiFi Software for Windows stems from improper authentication associated with device drivers operating at Ring 2, allowing a local, unauthenticated user to gain elevated privileges. This is a classic authentication bypass (CWE‑287) that can facilitate local code execution. The immediate impact on the vulnerable system is low confidentiality and no direct integrity or availability damage, but the consequence of successful exploitation could lead to high confidentiality compromise and moderate reductions in integrity and availability across the system.
Affected Systems
The affected product is Intel PROSet/Wireless WiFi Software for Windows. Specific component versions were not disclosed in the advisory, so any installation of the current driver package should be considered vulnerable.
Risk and Exploitability
The CVSS score of 6.3 places this issue in the moderate severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local privilege‑escalation scenario that requires no user interaction or special internal knowledge; an attacker who can run code locally on the target machine can exploit the driver flaw. Because the requirement for local access is a limiting factor, widespread attacks are unlikely but the impact of a successful event could be significant.
OpenCVE Enrichment