CVE-2025-30255

8.2

Intel · PROSet/Wireless WiFi Software

Intel PROSet/Wireless WiFi Software for Windows contains an out-of-bounds write vulnerability in device drivers that may allow an unauthenticated, adjacent attacker to cause a denial of service.

Executive summary

An out-of-bounds write vulnerability in Intel PROSet/Wireless WiFi Software for Windows allows unauthenticated, adjacent attackers to trigger a system denial of service.

Vulnerability

This vulnerability is an out-of-bounds write (CWE-787) occurring within Ring 2 device drivers. It allows an unauthenticated adversary with adjacent network access to trigger a denial of service condition with low attack complexity and no user interaction.

Business impact

The vulnerability carries a CVSS score of 8.2, classifying it as a high-severity issue primarily due to the potential for significant disruption to system availability. Successful exploitation could lead to intermittent or total system instability, causing operational downtime for affected devices. Because the attack vector is adjacent, the risk is most pronounced for systems operating in shared or public wireless environments.

Remediation

Immediate Action: Organizations should update Intel PROSet/Wireless WiFi Software to version 23.160 or later as specified in the official Intel security advisory INTEL-SA-01398.

Proactive Monitoring: Monitor system event logs for unexpected driver crashes, kernel panics, or repeated wireless interface restarts that may indicate an exploitation attempt.

Compensating Controls: Ensure that wireless network security protocols, such as WPA3, are enabled and that devices are isolated from untrusted traffic sources at the network level.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the nature of the impact on system availability, this update should be prioritized for all Windows endpoints utilizing affected Intel wireless hardware. Administrators must deploy the vendor-provided driver update to mitigate the risk of denial of service, especially for mobile devices that frequently connect to shared or public wireless networks.

More Intel CVEs

Sources