Junglewise Threat Intelligence

CVE-2026-20881: Intel QAT software drivers divide by zero in Ring 3 User Applications

CVE-2026-20881 · Severity: medium · CVSS 5.5 · Published 2026-05-12

Technologies: Intel QuickAssist Technology (QAT) Software Drivers for Windows, Intel Quickassist Technology. Vendors: Intel.

Executive brief

A vulnerability exists in Intel QuickAssist Technology (QAT) drivers for Windows, which are used to accelerate cryptographic and data compression workloads. An authenticated local attacker could exploit this flaw to cause a system crash or service interruption. This results in a denial of service, potentially impacting business operations that rely on these hardware acceleration features.

Technical details

A divide-by-zero vulnerability (CWE-369) exists in certain Intel QuickAssist Technology (QAT) software drivers for Windows before version 1.13. The flaw is located within Ring 3 (User Applications) components of the driver stack. An unprivileged but authenticated local adversary can trigger this condition through a low-complexity attack without requiring user interaction. Successful exploitation leads to a denial of service (DoS) by crashing the affected application or driver component. Intel has released version 1.13 and later to mitigate this issue.

Affected products

  • Intel QuickAssist Technology (QAT) software drivers for Windows before 1.13

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats