CVE-2015-2291
Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 March 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.01% probability · 95th percentile
- CISA KEV
- Listed 10 February 2023 · due 3 March 2023 · used in ransomware campaigns
- Weakness
- CWE-20
- Affected
- intel/ethernet diagnostics driver iqvw32.sys · intel/ethernet diagnostics driver iqvw64.sys
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291
References
- http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/79623Broken Link, Third Party Advisory, VDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-frPatch, Vendor Advisory
- https://www.exploit-db.com/exploits/36392/Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/79623Broken Link, Third Party Advisory, VDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-frPatch, Vendor Advisory
- https://www.exploit-db.com/exploits/36392/Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2291US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.