CVE-2015-2291
intel ethernet diagnostics driver iqvw32.sys, intel ethernet diagnostics driver iqvw64.sys
Published 9 Aug 2017 · updated 1 Oct 2026 · Analyzed
7.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Feb 2023, with a remediation deadline of 3 Mar 2023 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
References
- packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html · Third Party Advisory, VDB Entry
- www.securityfocus.com/bid/79623 · Broken Link, Third Party Advisory, VDB Entry
- security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr · Patch, Vendor Advisory
- www.exploit-db.com/exploits/36392/ · Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2291 · US Government Resource