Executive brief
A vulnerability in the software for Intel QuickAssist Adapter 8960 could allow a local user to gain higher-level system privileges. This hardware is typically used to accelerate data compression and cryptography tasks in servers. An attacker with existing access to the system could exploit this flaw to compromise the confidentiality and integrity of the entire system.
Technical details
An untrusted pointer dereference vulnerability (CWE-822) exists in the Intel QuickAssist Adapter 8960 software drivers for Windows before version 1.13. The flaw resides within Ring 3 user applications. A local, authenticated attacker can exploit this vulnerability with low complexity and no user interaction to achieve an escalation of privilege. Successful exploitation grants the attacker high confidentiality, integrity, and availability impacts on the local system. Intel has released version 1.13 to mitigate this issue.
Affected products
- Intel QuickAssist Adapter 8960 software before 1.13
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory