VYPR
Unrated severityNVD Advisory· Published Feb 14, 2024· Updated Aug 16, 2024

CVE-2023-22848

CVE-2023-22848

Description

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper access control in Intel Thunderbolt DCH drivers before version 88 allows an authenticated user to cause denial of service via local access.

Vulnerability

An improper access control vulnerability exists in some Intel(R) Thunderbolt(TM) DCH drivers for Windows versions before 88. The flaw resides in the driver's handling of access permissions, allowing an authenticated user to interact with the driver in ways that lead to denial of service. Affected versions include all driver releases prior to version 88 [1].

Exploitation

To exploit this vulnerability, an attacker must have local access to the system and be authenticated (e.g., as a standard user). The attacker can then leverage the improper access controls to trigger a denial of service condition by sending specially crafted requests to the driver, likely causing the system or Thunderbolt functionality to become unresponsive [1].

Impact

Successful exploitation results in a denial of service, impacting system availability. The attacker gains no additional privileges and the scope of compromise is limited to local disruption of the affected driver or system [1].

Mitigation

Intel has released driver version 88 to address this vulnerability. Users should update to the latest version available from Intel's support site or via Windows Update. No workarounds have been provided; updating is the recommended mitigation [1].

References
  1. INTEL-SA-00851

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.