February 10, 2023 · Applied Cybernetics Group
CVE-2015-2291 — Intel Ethernet Diagnostics Driver for Windows
known ransomware use
Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability
- Added to KEV
2023-02-10- Federal due date
2023-03-03- Vendor
- Intel
- Product
- Ethernet Diagnostics Driver for Windows
- EPSS
- 95.0th percentile (score 0.090, as of
2026-09-16) - NVD CVSS v3.1
- 7.8 (HIGH)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2015-2291
CISA short description
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
Required action
Apply updates per vendor instructions.
NVD description
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.