VYPR
Unrated severityNVD Advisory· Published Feb 14, 2024· Updated Aug 8, 2024

CVE-2023-27300

CVE-2023-27300

Description

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper buffer restrictions in Intel Thunderbolt DCH drivers for Windows before version 88 allow an authenticated user to disclose information via local access.

Vulnerability

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to disclose information via local access. The vulnerability arises when a user-mode process sends malformed input to the driver, causing it to read beyond the intended buffer boundaries. Affected versions include all driver releases prior to 88 [1].

Exploitation

An authenticated user on the local system can exploit this vulnerability by sending specially crafted IOCTL requests to the Thunderbolt driver. No additional privileges beyond standard user access are required. The attacker triggers an out-of-bounds read by manipulating input parameters, causing the driver to expose kernel memory contents [1].

Impact

Successful exploitation leads to information disclosure (confidentiality breach). An attacker may be able to read sensitive kernel memory, including passwords, cryptographic keys, or other user data. The attack does not require elevated privileges but does require local access to the target system [1].

Mitigation

Intel has released driver version 88 to address this issue. Users and administrators should update the Thunderbolt driver to version 88 or later through their system vendor or Intel's official channels. There is no known workaround for older versions; applying the fix is the sole mitigation [1].

References
  1. INTEL-SA-00851

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.