Cyber Posture

CVE-2024-41168

High

Published: 12 February 2025

Published
12 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score 0.0009 24.7th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Use after free in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

Security Summary

CVE-2024-41168 is a use-after-free vulnerability (CWE-416) affecting Intel PROSet/Wireless WiFi and Killer™ WiFi software for Windows versions prior to 23.80. The flaw resides in the WiFi drivers, where freed memory is accessed post-deallocation, potentially leading to crashes or instability. It carries a CVSS v3.1 base score of 7.4 (AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), indicating high severity due to its impact on availability with a changed scope.

An unauthenticated attacker with adjacent network access can exploit this vulnerability to trigger a denial-of-service condition. Exploitation requires local network proximity, such as from a nearby device on the same WiFi network or wired segment, with low complexity and no user interaction or privileges needed. Successful attacks result in high-impact availability disruption, potentially causing the affected WiFi software to crash and rendering wireless connectivity unavailable.

Intel's security advisory (INTEL-SA-01224) at https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html details mitigation, recommending an update to version 23.80 or later of the affected software, which addresses the use-after-free issue. Practitioners should verify installations via Intel's driver update tools and monitor for patches on supported Windows systems.

Details

CWE(s)
CWE-416

References