ZeroHour

CVE-2015-2291

KEV ransomwaremass1

Input Validation DoS Flaw in Intel Ethernet Diagnostics Driver for Windows

CISA: Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

CVSS
EPSS
9%p95
Published
KEV added
AI analysis

CVE-2015-2291 is an input-validation flaw (CWE-20) in the Windows kernel-mode driver files IQVW32.sys and IQVW64.sys that ship with Intel's Ethernet diagnostics software for Windows. It is triggered when the driver mishandles malformed or unexpected input (such as a crafted request from code running on the host), causing the affected Windows system to crash. An attacker gains denial of service — a system-wide crash or blue-screen — on any Windows machine where the vulnerable diagnostics drivers are installed, a technique CISA notes has been used in ransomware operations. Any Windows workstation or server running the Intel Ethernet Diagnostics Driver is affected. Exploitation is in the wild: CISA added the flaw to the KEV catalog on 2023-02-10 with known ransomware use; EPSS estimates a 9.0% probability of exploitation in the next 30 days (95th percentile), and no public PoC is known.

What to do: Inventory Windows hosts for the driver files IQVW32.sys and IQVW64.sys (including driver service entries) to determine exposure, then apply updated Intel Ethernet diagnostics/network drivers per Intel's instructions, as required by CISA's KEV listing. Given known ransomware use, prioritize high-value servers and endpoints where untrusted code or users run. Restricting local code execution to trusted users reduces exposure until updates are applied.

Affected
Intel Ethernet Diagnostics Driver for Windows
Estimated exposure
mass≈ millions of Windows endpoints plausibly carry these Intel diagnostics drivers; exact count unknown — Estimated from the ubiquity of onboard Intel Ethernet controllers in business-class Windows PCs and servers and the distribution of these diagnostics drivers within Intel's widely deployed network software suites; no public install counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).

CISA Known Exploited Vulnerability
Affected
Intel Ethernet Diagnostics Driver for Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Intel
Products
Ethernet Diagnostics Driver for Windows
Weakness
CWE-20

In the news