Executive brief
Intel QuickAssist Technology (QAT) is a hardware acceleration technology used to speed up intensive tasks like data encryption and compression. A vulnerability in certain Windows drivers for this technology could allow a local user to cause a system crash or service interruption. This would result in a denial of service, potentially halting business operations that rely on these acceleration features.
Technical details
A vulnerability classified as CWE-252 (Unchecked Return Value) exists in Intel QAT software drivers for Windows before version 1.13 within Ring 3 (User Applications). The flaw occurs when the driver fails to properly validate the return value of a function call, which can lead to unexpected behavior. An unprivileged, authenticated local adversary can exploit this with low complexity to trigger a denial of service. The attack requires no user interaction and no special internal knowledge of the system. Intel has released version 1.13 to mitigate this issue.
Affected products
- Intel QuickAssist Technology (QAT) software drivers for Windows before 1.13
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory