Qualcomm Windows WLAN Host Out-of-bounds Read Vulnerability

Vulnerability

A memory corruption vulnerability has been identified in the Windows WLAN Host. This issue arises from an IOCTL call initiated from user-space to write board data to the WLAN driver, leading to an out-of-bounds read condition. The vulnerability is present in various chipsets, including those used in Qualcomm's Snapdragon 8 Gen 1 and 8 Gen 3 mobile platforms, as well as in several automotive and IoT chipsets.

Impact

Exploitation of this vulnerability causes memory corruption, which can lead to undefined behavior such as arbitrary code execution or causing a system crash.

Reproduction

The vulnerability can be reproduced by sending an IOCTL call from user-space to the Windows WLAN Host, targeting the WLAN driver. This can be done using a custom application that interfaces with the WLAN driver via IOCTL calls, specifically those that write board data.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm April 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.6
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.