Cyber Resilience

CVE-2023-26592

Deserialization in Intel Thunderbolt Dch Driver ≤ 88

Published
14 February 2024
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 3.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
EPSS Score 0.0037 30th percentile
Risk Priority 17 floored blend · peak EPSS

Summary

CVE-2023-26592 is a low-severity Deserialization of Untrusted Data (CWE-502) vulnerability in Intel Thunderbolt Dch Driver. Its CVSS base score is 3.8 (Low).

Operationally, ranked at the 30th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable a denial of service via local access.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-22848Same product: Intel Thunderbolt Dch Driver
CVE-2023-27308Same product: Intel Thunderbolt Dch Driver
CVE-2023-27300Same product: Intel Thunderbolt Dch Driver
CVE-2023-26585Same product: Intel Thunderbolt Dch Driver
CVE-2023-22390Same product: Intel Thunderbolt Dch Driver
CVE-2023-24481Same product: Intel Thunderbolt Dch Driver
CVE-2023-25769Same product: Intel Thunderbolt Dch Driver
CVE-2023-26596Same product: Intel Thunderbolt Dch Driver
CVE-2023-27307Same product: Intel Thunderbolt Dch Driver
CVE-2023-24463Same product: Intel Thunderbolt Dch Driver

Affected Assets

intel
thunderbolt dch driver
≤ 88

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-502

Penetration testing supplies malicious serialized objects, detecting unsafe deserialization and supporting corrective actions.

addresses: CWE-502

Evaluation of untrusted data handling (deserialization testing) reveals unsafe processing, which the required remediation process addresses.

addresses: CWE-502

Untrusted serialized data can be deserialized and observed inside the chamber, blocking gadget-chain exploitation outside the sandbox.

addresses: CWE-502

Validates or rejects untrusted serialized data before deserialization occurs.

addresses: CWE-502

Identifies and blocks malicious code introduced through deserialization of untrusted data at system boundaries.

addresses: CWE-502

Integrity verification of serialized information can detect tampering before deserialization occurs.

addresses: CWE-502

Provenance of associated data allows detection of untrusted sources before deserialization or processing occurs.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-02 none match
prevents

PR.PS-02 addresses only post-deployment updates/patching and cannot prevent introduction of unsafe deserialization code, yet it can remediate some instances when the flaw exists in outdated libraries or components.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

Security testing includes validation of deserialization routines and the use of untrusted data, reducing the likelihood that unsafe object reconstruction will be deployed.

prevents

Requiring vetted libraries, regular updates and SAST before release reduces the likelihood that deserialization logic will accept and act on attacker-controlled serialized objects.

detects

Regular scanning of third-party libraries and timely patching reduce the likelihood that unsafe deserialization vulnerabilities remain active.

none

Mandatory malware scanning of data received over networks or storage media intercepts malicious serialized payloads before they are deserialized by the target application.

References