Qualcomm Windows WLAN Host Out-of-bounds Read Vulnerability

Vulnerability

A memory corruption vulnerability has been identified in the Windows WLAN Host. This issue arises when the WLAN driver reads board data via an IOCTL call, potentially leading to memory corruption. The vulnerability is present in various chipsets, including FastConnect 6700, FastConnect 6900, QCA6595AU, QCM5430, QCM6490, QCN7605, QCN7606, QCS5430, QCS6490, and several others. The vulnerability can be exploited locally, and it has been assigned a CVSS score of 7.8, indicating a high level of severity.

Impact

Exploitation of this vulnerability can lead to memory corruption, which may be exploited to execute arbitrary code or cause a denial-of-service condition.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm April 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
1.3
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.