Qualcomm Windows WLAN Host Buffer Over-read Vulnerability via FIPS Encryption IOCTL

Vulnerability

A memory corruption vulnerability has been identified in the Windows WLAN Host component of certain Qualcomm chipsets. This issue arises from a buffer over-read while processing FIPS encryption or decryption IOCTL calls initiated from user-space. The vulnerability could potentially be exploited to cause memory corruption, leading to undefined behavior in the application.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to arbitrary code execution or application crashes.

Remediation

Qualcomm has notified customers about this vulnerability and provided patch instructions. The patch can be applied by following the instructions available in the January 2025 Qualcomm Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.