Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability

cve CVE-2015-2291 3 sources, 3 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS). Apply updates per vendor instructions. https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291 the claim

What it is to other things

affectsintel/ethernet_diagnostics_driver_iqvw32.sys
NVD
affectsintel/ethernet_diagnostics_driver_iqvw64.sys
NVD
affectsmicrosoft/windows
NVD
made_byintel
NVD
made_bymicrosoft
NVD

In words only, so not counted until a person confirms one:

affectsn_a/n_a
NVD says “n/a · n/a”
made_byn_a
NVD says “n/a”

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBGlafkos Charalambous
receipt
Source
Exploit-DB
Its words
Glafkos Charalambous
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Glafkos Charalambous",
  "codes": "CVE-2015-2291;OSVDB-119634;OSVDB-119633",
  "date_added": "2015-03-16",
  "date_published": "2015-03-14",
  "date_updated": "2015-03-16",
  "description": "Intel Network Adapter Diagnostic Driver - IOCTL Handling",
  "file": "exploits/windows/dos/36392.txt",
  "id": "36392",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "dos",
  "verified": "0"
}
—
Cvss
cvss
NVD7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "cve@mitre.org"
      }
    ],
    "cisaActionDue": "2023-03-03",
    "cisaExploitAdd": "2023-02-10",
    "cisaRequiredAction": "Apply updates per vendor instructions.",
    "cisaVulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:intel:ethernet_diagnostics_driver_iqvw32.sys:1.03.0.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "94AFBAC8-D782-4CDC-B961-0EEAD97DA0A3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:intel:ethernet_diagnostics_driver_iqvw64.sys:1.03.0.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "B82125E5-B02D-4021-8D5C-DEB11C87CAFB",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call."
      },
      {
        "lang": "es",
        "value": "(1) IQVW32.sys en versiones anteriores a la 1.3.1.0 y (2) IQVW64.sys en versiones anteriores a la 1.3.1.0 en el controlador de diagnósticos de Intel Ethernet para Windows permite que usuarios locales provoquen una denegación de servicio o, posiblemente, ejecuten código arbitrario con privilegios kernel mediante una llamada IOCTL (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F o (d) 0x80862007 manipulada."
      }
    ],
    "id": "CVE-2015-2291",
    "lastModified": "2026-10-01T19:17:11.830",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": true,
          "baseSeverity": "HIGH",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "NONE",
            "availabilityImpact": "COMPLETE",
            "baseScore": 7.2,
            "confidentialityImpact": "COMPLETE",
            "integrityImpact": "COMPLETE",
            "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
            "version": "2.0"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 10.0,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "nvd@nist.gov",
          "type": "Primary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2015-2291",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-04T03:55:49.728526Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2017-08-09T18:29:00.933",
    "references": [
      {
        "source": "cve@mitre.org",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Broken Link",
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://www.securityfocus.com/bid/79623"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://www.exploit-db.com/exploits/36392/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Broken Link",
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://www.securityfocus.com/bid/79623"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://www.exploit-db.com/exploits/36392/"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2291"
      }
    ],
    "sourceIdentifier": "cve@mitre.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-20
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-20
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 00:06 UTC
What the source handed over
{
  "cveID": "CVE-2015-2291",
  "cwes": "CWE-20",
  "dateAdded": "2023-02-10",
  "dueDate": "2023-03-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291",
  "product": "Ethernet Diagnostics Driver for Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).",
  "vendorProject": "Intel",
  "vulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2023-03-03
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2023-03-03
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 00:06 UTC
What the source handed over
{
  "cveID": "CVE-2015-2291",
  "cwes": "CWE-20",
  "dateAdded": "2023-02-10",
  "dueDate": "2023-03-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291",
  "product": "Ethernet Diagnostics Driver for Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).",
  "vendorProject": "Intel",
  "vulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 00:06 UTC
What the source handed over
{
  "cveID": "CVE-2015-2291",
  "cwes": "CWE-20",
  "dateAdded": "2023-02-10",
  "dueDate": "2023-03-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291",
  "product": "Ethernet Diagnostics Driver for Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).",
  "vendorProject": "Intel",
  "vulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 00:06 UTC
What the source handed over
{
  "cveID": "CVE-2015-2291",
  "cwes": "CWE-20",
  "dateAdded": "2023-02-10",
  "dueDate": "2023-03-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291",
  "product": "Ethernet Diagnostics Driver for Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).",
  "vendorProject": "Intel",
  "vulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesKnown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Known
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 00:06 UTC
What the source handed over
{
  "cveID": "CVE-2015-2291",
  "cwes": "CWE-20",
  "dateAdded": "2023-02-10",
  "dueDate": "2023-03-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291",
  "product": "Ethernet Diagnostics Driver for Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).",
  "vendorProject": "Intel",
  "vulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability"
}
—
Platform
platform
Exploit-DBwindows
receipt
Source
Exploit-DB
Its words
windows
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Glafkos Charalambous",
  "codes": "CVE-2015-2291;OSVDB-119634;OSVDB-119633",
  "date_added": "2015-03-16",
  "date_published": "2015-03-14",
  "date_updated": "2015-03-16",
  "description": "Intel Network Adapter Diagnostic Driver - IOCTL Handling",
  "file": "exploits/windows/dos/36392.txt",
  "id": "36392",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "dos",
  "verified": "0"
}
—
Product
product
not compared
CISA Known Exploited VulnerabilitiesEthernet Diagnostics Driver for Windows
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Ethernet Diagnostics Driver for Windows
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 00:06 UTC
What the source handed over
{
  "cveID": "CVE-2015-2291",
  "cwes": "CWE-20",
  "dateAdded": "2023-02-10",
  "dueDate": "2023-03-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291",
  "product": "Ethernet Diagnostics Driver for Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).",
  "vendorProject": "Intel",
  "vulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability"
}
—
Product
product
not compared
NVDn/a
receipt
Source
NVD
Its words
n/a
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "cve@mitre.org"
      }
    ],
    "cisaActionDue": "2023-03-03",
    "cisaExploitAdd": "2023-02-10",
    "cisaRequiredAction": "Apply updates per vendor instructions.",
    "cisaVulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:intel:ethernet_diagnostics_driver_iqvw32.sys:1.03.0.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "94AFBAC8-D782-4CDC-B961-0EEAD97DA0A3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:intel:ethernet_diagnostics_driver_iqvw64.sys:1.03.0.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "B82125E5-B02D-4021-8D5C-DEB11C87CAFB",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call."
      },
      {
        "lang": "es",
        "value": "(1) IQVW32.sys en versiones anteriores a la 1.3.1.0 y (2) IQVW64.sys en versiones anteriores a la 1.3.1.0 en el controlador de diagnósticos de Intel Ethernet para Windows permite que usuarios locales provoquen una denegación de servicio o, posiblemente, ejecuten código arbitrario con privilegios kernel mediante una llamada IOCTL (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F o (d) 0x80862007 manipulada."
      }
    ],
    "id": "CVE-2015-2291",
    "lastModified": "2026-10-01T19:17:11.830",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": true,
          "baseSeverity": "HIGH",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "NONE",
            "availabilityImpact": "COMPLETE",
            "baseScore": 7.2,
            "confidentialityImpact": "COMPLETE",
            "integrityImpact": "COMPLETE",
            "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
            "version": "2.0"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 10.0,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "nvd@nist.gov",
          "type": "Primary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2015-2291",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-04T03:55:49.728526Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2017-08-09T18:29:00.933",
    "references": [
      {
        "source": "cve@mitre.org",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Broken Link",
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://www.securityfocus.com/bid/79623"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://www.exploit-db.com/exploits/36392/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Broken Link",
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://www.securityfocus.com/bid/79623"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://www.exploit-db.com/exploits/36392/"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2291"
      }
    ],
    "sourceIdentifier": "cve@mitre.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "cve@mitre.org"
      }
    ],
    "cisaActionDue": "2023-03-03",
    "cisaExploitAdd": "2023-02-10",
    "cisaRequiredAction": "Apply updates per vendor instructions.",
    "cisaVulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:intel:ethernet_diagnostics_driver_iqvw32.sys:1.03.0.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "94AFBAC8-D782-4CDC-B961-0EEAD97DA0A3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:intel:ethernet_diagnostics_driver_iqvw64.sys:1.03.0.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "B82125E5-B02D-4021-8D5C-DEB11C87CAFB",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call."
      },
      {
        "lang": "es",
        "value": "(1) IQVW32.sys en versiones anteriores a la 1.3.1.0 y (2) IQVW64.sys en versiones anteriores a la 1.3.1.0 en el controlador de diagnósticos de Intel Ethernet para Windows permite que usuarios locales provoquen una denegación de servicio o, posiblemente, ejecuten código arbitrario con privilegios kernel mediante una llamada IOCTL (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F o (d) 0x80862007 manipulada."
      }
    ],
    "id": "CVE-2015-2291",
    "lastModified": "2026-10-01T19:17:11.830",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": true,
          "baseSeverity": "HIGH",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "NONE",
            "availabilityImpact": "COMPLETE",
            "baseScore": 7.2,
            "confidentialityImpact": "COMPLETE",
            "integrityImpact": "COMPLETE",
            "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
            "version": "2.0"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 10.0,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "nvd@nist.gov",
          "type": "Primary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2015-2291",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-04T03:55:49.728526Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2017-08-09T18:29:00.933",
    "references": [
      {
        "source": "cve@mitre.org",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Broken Link",
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://www.securityfocus.com/bid/79623"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://www.exploit-db.com/exploits/36392/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Broken Link",
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://www.securityfocus.com/bid/79623"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://www.exploit-db.com/exploits/36392/"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2291"
      }
    ],
    "sourceIdentifier": "cve@mitre.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Type
type
Exploit-DBdos
receipt
Source
Exploit-DB
Its words
dos
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Glafkos Charalambous",
  "codes": "CVE-2015-2291;OSVDB-119634;OSVDB-119633",
  "date_added": "2015-03-16",
  "date_published": "2015-03-14",
  "date_updated": "2015-03-16",
  "description": "Intel Network Adapter Diagnostic Driver - IOCTL Handling",
  "file": "exploits/windows/dos/36392.txt",
  "id": "36392",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "dos",
  "verified": "0"
}
—
Vendor
vendor
NVDn/a
receipt
Source
NVD
Its words
n/a
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-03 00:06 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "n/a",
            "vendor": "n/a",
            "versions": [
              {
                "status": "affected",
                "version": "n/a"
              }
            ]
          }
        ],
        "source": "cve@mitre.org"
      }
    ],
    "cisaActionDue": "2023-03-03",
    "cisaExploitAdd": "2023-02-10",
    "cisaRequiredAction": "Apply updates per vendor instructions.",
    "cisaVulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability",
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:intel:ethernet_diagnostics_driver_iqvw32.sys:1.03.0.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "94AFBAC8-D782-4CDC-B961-0EEAD97DA0A3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:intel:ethernet_diagnostics_driver_iqvw64.sys:1.03.0.7:*:*:*:*:*:*:*",
                "matchCriteriaId": "B82125E5-B02D-4021-8D5C-DEB11C87CAFB",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call."
      },
      {
        "lang": "es",
        "value": "(1) IQVW32.sys en versiones anteriores a la 1.3.1.0 y (2) IQVW64.sys en versiones anteriores a la 1.3.1.0 en el controlador de diagnósticos de Intel Ethernet para Windows permite que usuarios locales provoquen una denegación de servicio o, posiblemente, ejecuten código arbitrario con privilegios kernel mediante una llamada IOCTL (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F o (d) 0x80862007 manipulada."
      }
    ],
    "id": "CVE-2015-2291",
    "lastModified": "2026-10-01T19:17:11.830",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": true,
          "baseSeverity": "HIGH",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "NONE",
            "availabilityImpact": "COMPLETE",
            "baseScore": 7.2,
            "confidentialityImpact": "COMPLETE",
            "integrityImpact": "COMPLETE",
            "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
            "version": "2.0"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 10.0,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "nvd@nist.gov",
          "type": "Primary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2015-2291",
            "options": [
              {
                "exploitation": "active"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-08-04T03:55:49.728526Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2017-08-09T18:29:00.933",
    "references": [
      {
        "source": "cve@mitre.org",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Broken Link",
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://www.securityfocus.com/bid/79623"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr"
      },
      {
        "source": "cve@mitre.org",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://www.exploit-db.com/exploits/36392/"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://packetstormsecurity.com/files/130854/Intel-Network-Adapter-Diagnostic-Driver-IOCTL-DoS.html"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Broken Link",
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "http://www.securityfocus.com/bid/79623"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Patch",
          "Vendor Advisory"
        ],
        "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00051&languageid=en-fr"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://www.exploit-db.com/exploits/36392/"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "tags": [
          "US Government Resource"
        ],
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2015-2291"
      }
    ],
    "sourceIdentifier": "cve@mitre.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-20"
          }
        ],
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesIntel
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Intel
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-03 00:06 UTC
What the source handed over
{
  "cveID": "CVE-2015-2291",
  "cwes": "CWE-20",
  "dateAdded": "2023-02-10",
  "dueDate": "2023-03-03",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00051.html; https://nvd.nist.gov/vuln/detail/CVE-2015-2291",
  "product": "Ethernet Diagnostics Driver for Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).",
  "vendorProject": "Intel",
  "vulnerabilityName": "Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-03 00:04 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Glafkos Charalambous",
  "codes": "CVE-2015-2291;OSVDB-119634;OSVDB-119633",
  "date_added": "2015-03-16",
  "date_published": "2015-03-14",
  "date_updated": "2015-03-16",
  "description": "Intel Network Adapter Diagnostic Driver - IOCTL Handling",
  "file": "exploits/windows/dos/36392.txt",
  "id": "36392",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "dos",
  "verified": "0"
}
—

vulnerability

Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability
zetlyn/cve-kev · 2023-02-10
cwes CWE-20 due_date 2023-03-03 exploited yes forensic_triage false known_ransomware_campaign_use Known product Ethernet Diagnostics Driver for Windows vendor_project Intel
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
zetlyn/cve-nvd · 2017-08-09
cvss 7.8 product n/a status Analyzed vendor n/a source

exploit

Intel Network Adapter Diagnostic Driver - IOCTL Handling
zetlyn/cve-exploitdb · 2015-03-14
author Glafkos Charalambous platform windows type dos verified false source