Untrusted Pointer Dereference in Intel QuickAssist Technology Software
CVE-2025-32446

6.8MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
11 November 2025

What is CVE-2025-32446?

A vulnerability exists in the Intel QuickAssist Technology software prior to version 2.6.0, where an untrusted pointer dereference can lead to privilege escalation. This issue allows an adversary with authenticated system access to potentially manipulate data, enabling them to execute a low-complexity attack without requiring user interaction. Exploitation of this vulnerability may compromise the integrity of the affected system, while the overall confidentiality and availability remain unaffected. Additionally, successful exploitation requires no special internal knowledge, potentially allowing adversaries to escalate privileges and access sensitive data.

Affected Version(s)

Intel QuickAssist Technology software before version 2.6.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32446 : Untrusted Pointer Dereference in Intel QuickAssist Technology Software