Junglewise Threat Intelligence

CVE-2015-2291: Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

CVE-2015-2291 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-02-10

Vendors: Intel.

Executive brief

The Intel Ethernet diagnostics driver for Windows (IQVW32.sys and IQVW64.sys) contains a vulnerability in its IOCTL handling. Local users can issue crafted IOCTL calls to cause a denial of service or potentially execute arbitrary code with kernel privileges.

Affected products

  • Intel Ethernet diagnostics driver IQVW32.sys before 1.3.1.0
  • Intel Ethernet diagnostics driver IQVW64.sys before 1.3.1.0

Timeline

  • 2017-08-09: disclosed: NVD Published Date
  • 2023-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog