SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2015-2291

Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

KEVHIGH 7.8EPSS 9.01%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 March 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
9.01% probability · 95th percentile
CISA KEV
Listed 10 February 2023 · due 3 March 2023 · used in ransomware campaigns
Weakness
CWE-20
Affected
intel/ethernet diagnostics driver iqvw32.sys · intel/ethernet diagnostics driver iqvw64.sys
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.