EXPOSURES › CVE-2015-2291
CVE-2015-2291
CRITICAL ⌖ ON CISA KEV · EXPLOITEDIntel's Ethernet Diagnostics Driver for Windows had a DoS vulnerability that was actively exploited in the wild and linked to ransomware attacks.
The vulnerability in the IQVW32.sys and IQVW64.sys drivers allowed attackers to cause denial-of-service, which was actively exploited in the wild and linked to ransomware. DIB organizations must ensure all Intel Ethernet Diagnostics drivers are patched to prevent service disruption and potential ransomware entry points. This failure highlights the risk of unpatched, actively exploited vulnerabilities in widely deployed hardware drivers.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware, indicating a severe, avoidable failure that compromised system availability and served as an entry point for malicious actors.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).