CVE-2015-2291

CVE Published 2017-08-09
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) intel
Related Product(s) ethernet_diagnostics_driver_iqvw64.sys, ethernet_diagnostics_driver_iqvw32.sys
Exploitation Reported (CISA KEV) 2023-02-10
CVSS 3 Base Score 7.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References