Executive brief
A vulnerability in Intel QuickAssist Technology (QAT) drivers for Windows could allow a local user to cause a system crash or service interruption. Intel QAT is used to accelerate compute-intensive tasks like encryption and data compression. An exploit would result in a denial of service, potentially disrupting business operations that rely on these hardware acceleration features.
Technical details
A vulnerability classified as improper input validation (CWE-20) exists in the Ring 3 (User Applications) component of Intel QuickAssist Technology (QAT) software drivers for Windows. An authenticated, unprivileged local attacker can exploit this flaw by providing specially crafted input to the driver. Successful exploitation allows the attacker to trigger a denial of service (DoS) condition, impacting system availability. The vulnerability is mitigated in version 1.13 and later.
Affected products
- Intel QuickAssist Technology (QAT) software drivers for Windows before 1.13
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory