Executive brief
A vulnerability in the Intel Data Center Graphics Driver for VMware ESXi could allow a privileged user to cause a system crash or corrupt data. This driver is responsible for managing graphics hardware within virtualized data center environments. An exploit could lead to a denial of service, impacting the availability of virtual machines and the integrity of the host system.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists within the Ring 1 device driver component of the Intel Data Center Graphics Driver for VMware ESXi. The flaw is triggered via local access by a privileged system software adversary. Because the driver operates at a high privilege level (Ring 1), an out-of-bounds write can result in high integrity and availability impacts, including system instability or data corruption. The vulnerability requires no special internal knowledge or user interaction to exploit. Intel has released version 2.0.2 to mitigate this issue.
Affected products
- Intel Data Center Graphics Driver for VMware ESXi before 2.0.2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched