Executive brief
A vulnerability in the Intel Data Center Graphics Driver for VMware ESXi could allow a privileged user to crash the system or access sensitive information. This driver is responsible for managing graphics hardware within virtualized data center environments. An exploit could lead to a denial of service or the exposure of data that should otherwise be protected from the user.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists within the Ring 1 device driver component of the Intel Data Center Graphics Driver for VMware ESXi. The flaw is triggered when the driver reads data outside the intended buffer boundaries. A local attacker with high privileges (system software adversary) can exploit this with low complexity to cause a denial of service or gain unauthorized access to sensitive system information. The vulnerability has been addressed in version 2.0.2 of the driver.
Affected products
- Intel Data Center Graphics Driver for VMware ESXi before 2.0.2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched: Fixed in version 2.0.2