Junglewise Threat Intelligence

CVE-2026-20782: Intel QAT software drivers buffer overflow in Ring 3 applications

CVE-2026-20782 · Severity: medium · CVSS 6.6 · Published 2026-05-12

Technologies: Intel QAT software drivers for Windows, Intel Quickassist Technology. Vendors: Intel.

Executive brief

Intel QuickAssist Technology (QAT) software drivers, which are used to accelerate cryptographic and data compression workloads, contain a security vulnerability. A local user with basic access to a system could exploit this flaw to cause the software to crash or become unresponsive. This would disrupt services relying on QAT acceleration and could lead to a full denial of service for those applications.

Technical details

A classic buffer overflow (CWE-120) exists in certain Intel QuickAssist Technology (QAT) software drivers for Windows within Ring 3 (User Applications). The vulnerability is triggered by improper input handling when copying data to a buffer without adequate size verification. An authenticated, unprivileged local attacker can exploit this with low complexity and no user interaction. Successful exploitation primarily impacts system availability by causing a denial of service, though it may also result in low-impact compromises to confidentiality and integrity. Intel has released version 1.13 to mitigate this issue.

Affected products

  • Intel QAT software drivers for Windows before 1.13

Timeline

  • 2026-05-12: advisory: Intel released SA-01387
  • 2026-05-12: disclosed: CVE-2026-20782 published

References

Related threats