Untrusted Pointer Dereference Vulnerability in Intel QAT Software
CVE-2023-32277

4.3MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
12 February 2025

What is CVE-2023-32277?

The I/O subsystem of Intel QAT software prior to version 2.0.5 is susceptible to an untrusted pointer dereference vulnerability. This flaw may enable an authenticated user to exploit local operating system access, leading to potential information disclosure. Proper safeguards and mitigation strategies should be implemented to prevent unauthorized access and protect sensitive data.

Affected Version(s)

Intel(R) QAT software before version 2.0.5

References

CVSS V4

Score:
4.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.