Junglewise Threat Intelligence

CVE-2026-20714: Intel QAT software drivers for Windows out-of-bounds write

CVE-2026-20714 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Intel QuickAssist Technology (QAT) Software Drivers for Windows, Intel Quickassist Technology. Vendors: Intel.

Executive brief

Intel QuickAssist Technology (QAT) is a hardware acceleration technology used to speed up intensive tasks like data encryption and compression. A security flaw in the Windows drivers for this technology could allow a person with low-level access to a computer to gain higher-level administrative privileges. This could lead to a full system takeover, allowing an attacker to access sensitive data or disable security protections.

Technical details

An out-of-bounds write vulnerability exists in the Ring 3 (User Applications) component of certain Intel QAT software drivers for Windows. The flaw is triggered when the driver fails to properly validate memory boundaries during write operations. An authenticated, unprivileged local attacker can exploit this by executing a low-complexity attack to overwrite memory, potentially leading to an escalation of privilege or full system compromise. The vulnerability is addressed in Intel QAT software driver version 1.13 and later.

Affected products

  • Intel QuickAssist Technology (QAT) software drivers for Windows before 1.13

Timeline

  • 2026-05-12: advisory: Intel released security advisory INTEL-SA-01387
  • 2026-05-12: disclosed: CVE-2026-20714 published to NVD

References

Related threats