Cyber Posture

CVE-2024-39356

High

Published: 12 February 2025

Published
12 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score 0.0006 17.2th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

NULL pointer dereference in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

Security Summary

CVE-2024-39356 is a NULL pointer dereference vulnerability, classified under CWE-476, affecting Intel(R) PROSet/Wireless WiFi and Killer™ WiFi software for Windows in versions prior to 23.80. Published on 2025-02-12, it carries a CVSS v3.1 base score of 7.4 (AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), indicating high severity primarily due to its potential for significant availability impact with a changed scope.

An unauthenticated attacker with adjacent network access can exploit this vulnerability with low complexity and no user interaction required. Successful exploitation may enable a denial of service condition on the affected system.

Intel's security advisory at https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html addresses this issue, with mitigation achieved by updating the affected software to version 23.80 or later.

Details

CWE(s)
CWE-476

References