Executive brief
Intel QuickAssist Technology (QAT) software drivers for Windows are used to accelerate cryptographic and data compression workloads. A vulnerability in these drivers could allow a local user to crash the system or specific applications, leading to a denial of service. This could disrupt business operations that rely on high-performance data processing.
Technical details
A NULL pointer dereference (CWE-476) exists in certain Intel QAT software drivers for Windows within Ring 3 (User Applications). The vulnerability is triggered when the driver fails to properly validate a pointer before dereferencing it. An unprivileged but authenticated local attacker can exploit this flaw with low complexity to cause a denial of service (system or application crash). The issue is resolved in Intel QAT software driver version 2.6.0 and later. No user interaction is required for exploitation.
Affected products
- Intel QuickAssist Technology (QAT) software drivers for Windows before 2.6.0
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory