Junglewise Threat Intelligence

CVE-2025-36510: Intel Display Virtualization for Windows buffer overflow in device driver

CVE-2025-36510 · Severity: info · CVSS 6.8 · Published 2026-05-12

Vendors: Intel.

Executive brief

A vulnerability in Intel's Display Virtualization drivers for Windows could allow a local user to crash the system. This software is used to manage graphics resources in virtualized environments, such as those used for running multiple operating systems or secure containers on a single PC. An exploit would result in a denial of service, potentially disrupting business operations and causing unsaved data loss, though it does not allow for data theft.

Technical details

A vulnerability classified as Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) exists in Intel Display Virtualization for Windows OS driver software within Ring 2 (Device Drivers). The flaw is caused by improper buffer restrictions when handling specific inputs. A local, authenticated attacker with low privileges can exploit this vulnerability without user interaction to trigger a system crash or hang (Denial of Service). The issue affects multiple Intel processor families including Alder Lake, Raptor Lake, Meteor Lake, and Arrow Lake. Intel has released driver version 2119 and later to mitigate this issue.

Affected products

  • Intel Display Virtualization for Windows OS driver software before version 2119

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-12: patched

References