Executive brief
A vulnerability in Intel QuickAssist Technology (QAT) drivers for Windows could allow a local user to gain elevated system privileges. Intel QAT is a hardware acceleration technology used to speed up intensive tasks like data encryption and compression. If exploited, an attacker who already has basic access to a computer could take full control of the system, potentially compromising sensitive data or disrupting operations.
Technical details
An improper input validation vulnerability (CWE-20) exists in certain Intel QuickAssist Technology (QAT) software drivers for Windows prior to version 1.13. The flaw is located within Ring 3 (User Applications) components of the driver suite. A local, authenticated attacker can exploit this vulnerability by providing specially crafted input to the driver, leading to an escalation of privilege. The attack is characterized by low complexity and requires no user interaction. Successful exploitation grants the attacker high confidentiality, integrity, and availability impacts on the local system. Intel has released version 1.13 to mitigate this issue.
Affected products
- Intel QuickAssist Technology (QAT) software drivers for Windows before 1.13
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory