Executive brief
A security vulnerability exists in Qualcomm Windows drivers that manage communication with trusted applications. An attacker with high-level administrative privileges on a local system could exploit this flaw to cause memory corruption. This could lead to a complete system crash or allow the attacker to gain further control over the underlying hardware and secure processing environments.
Technical details
A stack-based buffer overflow (CWE-121) exists in Qualcomm Windows drivers. The vulnerability is triggered when the driver processes an incorrectly formatted request intended for a trusted application. An attacker requires local access and high privileges (PR:H) to exploit this flaw. Successful exploitation results in memory corruption, which can be leveraged to achieve local privilege escalation or a denial-of-service (system crash) within the Windows kernel environment. The issue was disclosed in Qualcomm's June 2026 security bulletin.
Affected products
- Qualcomm Windows Drivers
Timeline
- 2026-06-01: disclosed: Initial publication by Qualcomm and NVD.
- 2026-06-01: advisory