CVE-2025-27713
7.8Intel · QAT Windows software
An out of bounds write vulnerability in Intel QAT Windows software before version 2.6.0 may allow an authenticated local user to escalate privileges.
Executive summary
A critical out of bounds write vulnerability in Intel QAT Windows software could allow an authenticated attacker to achieve local privilege escalation.
Vulnerability
This is an out of bounds write vulnerability (CWE-787) occurring within Ring 3 user applications. It requires an authenticated local user with specific internal knowledge to execute a high complexity attack to successfully escalate privileges.
Business impact
The exploitation of this vulnerability could result in a full compromise of local system security, leading to unauthorized privilege escalation and potential loss of system integrity. With a CVSS score of 7.8, this flaw represents a significant risk to organizational endpoints that rely on Intel QAT components, as it allows a low privileged attacker to bypass security boundaries.
Remediation
Immediate Action: Update Intel QAT Windows software to version 2.6.0 or later as specified in the official Intel security advisory.
Proactive Monitoring: Monitor system logs for unusual process execution or unauthorized attempts to interact with Intel QAT drivers and associated user space applications.
Compensating Controls: Implement strict local access controls and endpoint security policies to limit the capabilities of authenticated users, thereby reducing the attack surface for local privilege escalation attempts.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the potential for high impact on system integrity, administrators should prioritize the deployment of the vendor provided patch to all affected Windows systems. While the complexity of the attack provides a moderate barrier to entry, the risk of privilege escalation necessitates timely remediation to maintain a secure environment.