CVE-2025-35967: High severity Intel PROSet/Wireless WiFi software vulnerability
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-35967?
CVE-2025-35967 is classified as a medium severity vulnerability due to the potential for denial of service.
How do I fix CVE-2025-35967?
To mitigate CVE-2025-35967, users should update the Intel PROSet/Wireless WiFi Software to version 23.160 or higher.
What causes CVE-2025-35967?
CVE-2025-35967 is caused by an out-of-bounds read in the Intel PROSet/Wireless WiFi Software within device drivers.
Who is affected by CVE-2025-35967?
CVE-2025-35967 affects users of Intel PROSet/Wireless WiFi Software versions earlier than 23.160.
What types of attacks can exploit CVE-2025-35967?
CVE-2025-35967 can be exploited by unprivileged software adversaries using low complexity attacks to cause a denial of service.