PT-2014-1973 · Sentinelone+3 · Sentinelone+3
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Intel Ethernet diagnostics driver for Windows versions prior to 1.3.1.0
Description
Insufficient input validation in the
IQVW32.sys and IQVW64.sys drivers allows local users to cause a denial of service or execute arbitrary code with kernel privileges. This is achieved through crafted IOCTL (Input/Output Control) calls using the following codes: 0x80862013, 0x8086200B, 0x8086200F, or 0x80862007. The issue can be exploited using the METHOD NEITHER option. Real-world incidents involve the group Scattered Spider using a Bring Your Own Vulnerable Driver (BYOVD) technique, where they install these older, vulnerable drivers on compromised systems to bypass security solutions such as Microsoft Defender for Endpoint, Palo Alto Networks Cortex XDR, and SentinelOne, thereby gaining the highest privileges in Windows.Recommendations
Update the Intel Ethernet diagnostics driver to version 1.3.1.0 or later.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intel Ethernet Diagnostic Driver
Defender For Endpoint
Palo Alto Networks Cortex Xdr Agent
Sentinelone