Executive brief
Intel QuickAssist Technology (QAT) software drivers, which are used to accelerate cryptographic and data compression workloads, contain a security vulnerability. A local user with basic access to a system could exploit this flaw to cause the software to crash or become unresponsive. This would disrupt services relying on QAT acceleration and could lead to a full denial of service for those applications.
Technical details
A classic buffer overflow (CWE-120) exists in certain Intel QuickAssist Technology (QAT) software drivers for Windows within Ring 3 (User Applications). The vulnerability is triggered by improper input handling when copying data to a buffer without adequate size verification. An authenticated, unprivileged local attacker can exploit this with low complexity and no user interaction. Successful exploitation primarily impacts system availability by causing a denial of service, though it may also result in low-impact compromises to confidentiality and integrity. Intel has released version 1.13 to mitigate this issue.
Affected products
- Intel QAT software drivers for Windows before 1.13
Timeline
- 2026-05-12: advisory: Intel released SA-01387
- 2026-05-12: disclosed: CVE-2026-20782 published