Impact
A race condition that occurs between a check and a subsequent use in the Intel NPU Driver for Windows allows an unprivileged local user, who has authenticated to the system, to trigger a denial‑of‑service condition. The flaw does not expose data, but it can compromise system availability and, to a limited extent, integrity. The vulnerability is catalogued as a time‑of‑check time‑of‑use issue (CWE‑367). The exploitation requires a high‑complexity attack but does not require user interaction. The resulting impact is high availability loss with no direct confidentiality breach.
Affected Systems
The flaw affects all versions of the Intel(R) NPU Driver for Windows that operate at Ring 1. Each Windows system that installs or runs the NPU driver under these conditions is susceptible, regardless of the specific Windows version.
Risk and Exploitability
The CVSS score of 5.8 places the vulnerability in the moderate range, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an attacker must have local authenticated access but does not need elevated privileges. Because the flaw requires high attack complexity and no special knowledge, widespread exploitation is unlikely but not impossible in environments where the NPU driver is frequently loaded by unprivileged users.
OpenCVE Enrichment