← Vulnerability feed

Vulnerability record · CVE-2025-27713 · published 11 November 2025

CVE-2025-27713: Intel quickassist technology out-of-bounds write vulnerability

Intel · Quickassist Technology

Out-of-bounds write for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

7.3 CVSS 4.0 High EPSS 0.12% · top 98.4% CWE-787 · Out-of-bounds write
7.3CVSS 4.0 base score
0.12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Out-of-bounds write for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-27713 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-32641Intel quickassist technology improper input validation vulnerabilityImproper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service vi…EPSS 0.31%8.5CVE-2026-20767Intel quickassist technology improper input validation vulnerabilityImproper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow an escala…EPSS 0.11%8.5CVE-2026-20714Intel quickassist technology out-of-bounds write vulnerabilityOut-of-bounds write for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applications may allow a escalation of…EPSS 0.11%7.8CVE-2023-28740Intel quickassist technology library uncontrolled search path element vulnerabilityUncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to po…EPSS 0.19%7.8CVE-2023-28741Intel quickassist technology library classic buffer overflow vulnerabilityBuffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable e…EPSS 0.21%7.8CVE-2022-41699Intel quickassist technology incorrect permission assignment vulnerabilityIncorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user t…EPSS 0.17%7.8CVE-2022-40972Intel quickassist technology improper access control vulnerabilityImproper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalatio…EPSS 0.15%7.8CVE-2022-21804Intel quickassist technology out-of-bounds write vulnerabilityOut-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable …EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2025-27713), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.