← Vulnerability feed

Vulnerability record · CVE-2022-36397 · published 16 February 2023

CVE-2022-36397: Intel quickassist technology incorrect default permissions vulnerability

Intel · Quickassist Technology

Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

7.8 CVSS 3.1 High EPSS 0.23% · top 87.9% CWE-276 · Incorrect default permissions
7.8CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36397 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-32641Intel quickassist technology improper input validation vulnerabilityImproper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service vi…EPSS 0.31%8.5CVE-2026-20767Intel quickassist technology improper input validation vulnerabilityImproper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escala…EPSS 0.11%8.5CVE-2026-20714Intel quickassist technology out-of-bounds write vulnerabilityOut-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of…EPSS 0.11%7.8CVE-2023-28740Intel quickassist technology library uncontrolled search path element vulnerabilityUncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to po…EPSS 0.19%7.8CVE-2023-28741Intel quickassist technology library classic buffer overflow vulnerabilityBuffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable e…EPSS 0.21%7.8CVE-2022-41699Intel quickassist technology incorrect permission assignment vulnerabilityIncorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user t…EPSS 0.17%7.8CVE-2022-40972Intel quickassist technology improper access control vulnerabilityImproper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalatio…EPSS 0.15%7.8CVE-2022-21804Intel quickassist technology out-of-bounds write vulnerabilityOut-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable …EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2022-36397), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.