Executive brief
Intel QuickAssist Technology (QAT) software drivers for Windows are used to accelerate cryptographic and data compression workloads. A vulnerability in these drivers could allow a local user to crash the software, leading to a denial of service. This could disrupt applications relying on QAT for performance-critical tasks, though it does not allow for full system takeover.
Technical details
A NULL pointer dereference vulnerability exists in the Ring 3 (User Applications) component of certain Intel QuickAssist Technology (QAT) software drivers for Windows. The flaw is triggered when the driver fails to properly validate pointers before dereferencing them during application-level operations. An authenticated, unprivileged local attacker can exploit this by executing a low-complexity attack to crash the driver or associated user-mode applications. This results in a high impact on availability and a low impact on confidentiality. The issue is mitigated in version 1.13 and later.
Affected products
- Intel QuickAssist Technology (QAT) software drivers for Windows before 1.13
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory