CVE-2015-2291
Last modified
CVE-2015-2291 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.. CISA has confirmed active exploitation in the wild. EPSS estimates a 9.01% chance of exploitation in the next 30 days.
Description
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Ethernet Diagnostics Driver Iqvw32.Sys | 1.03.0.7 |
| Intel | Ethernet Diagnostics Driver Iqvw64.Sys | 1.03.0.7 |
References
- http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/79623Broken Link, Third Party Advisory, VDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-frPatch, Vendor Advisory
- https://www.exploit-db.com/exploits/36392/Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/79623Broken Link, Third Party Advisory, VDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-frPatch, Vendor Advisory
- https://www.exploit-db.com/exploits/36392/Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2291US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2015-2291?
How severe is CVE-2015-2291?
How do I fix CVE-2015-2291?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-2282Stack-based buffer overflow in the LZC decompression impleme…
- CVE-2015-2284userlogin.jsp in SolarWinds Firewall Security Manager (FSM) …
- CVE-2015-2285The logrotation script (/etc/cron.daily/upstart) in the Ubun…
- CVE-2015-2286lms/templates/footer-edx-new.html in Open edX edx-platform b…
- CVE-2015-2287Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-2289Cross-site scripting (XSS) vulnerability in templates/2k11/a…
- CVE-2015-2292Multiple SQL injection vulnerabilities in admin/class-bulk-e…
- CVE-2015-2293Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2015-2294Multiple cross-site scripting (XSS) vulnerabilities in the W…
- CVE-2015-2295Cross-site request forgery (CSRF) vulnerability in system_fi…
- CVE-2015-2296The resolve_redirects function in sessions.py in requests 2.…
- CVE-2015-2297nanohttp in libcsoap allows remote attackers to cause a deni…
Are you affected by CVE-2015-2291?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
