Executive brief
Intel QuickAssist Technology (QAT) software drivers, which are used to accelerate cryptographic and data compression tasks, contain a vulnerability that could allow a local user to crash the system. An authenticated attacker with low-level access to the computer could exploit this flaw to cause a denial of service, potentially disrupting business operations and system availability. This issue primarily impacts the reliability of the affected Windows systems.
Technical details
A vulnerability classified as improper input validation (CWE-20) exists in certain Intel QuickAssist Technology (QAT) software drivers for Windows within Ring 3 (User Applications). The flaw allows an unprivileged but authenticated local adversary to trigger a denial of service (DoS) condition. The attack is of low complexity and requires no user interaction or special internal knowledge of the system. While the primary impact is on system availability (High), there is also a low impact on confidentiality and integrity. Intel has released software updates to mitigate this issue; users should update to version 2.6 or later.
Affected products
- Intel QAT software drivers for Windows before version 2.6
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory