CVE-2024-39356
Published: 12 February 2025
Summary
CVE-2024-39356 is a high-severity NULL Pointer Dereference (CWE-476) vulnerability in Intel (inferred from references). Its CVSS base score is 7.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Application or System Exploitation (T1499.004); ranked at the 17.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-2 (Flaw Remediation) and RA-5 (Vulnerability Monitoring and Scanning).
Deeper analysis
CVE-2024-39356 is a NULL pointer dereference vulnerability, classified under CWE-476, affecting Intel(R) PROSet/Wireless WiFi and Killer™ WiFi software for Windows in versions prior to 23.80. Published on 2025-02-12, it carries a CVSS v3.1 base score of 7.4 (AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H), indicating high severity primarily due to its potential for significant availability impact with a changed scope.
An unauthenticated attacker with adjacent network access can exploit this vulnerability with low complexity and no user interaction required. Successful exploitation may enable a denial of service condition on the affected system.
Intel's security advisory at https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01224.html addresses this issue, with mitigation achieved by updating the affected software to version 23.80 or later.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-4917
Vulnerability details
NULL pointer dereference in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
NULL dereference in WiFi driver enables remote adjacent-network exploitation causing endpoint DoS via application/system crash.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly mitigates the CVE by requiring timely flaw remediation through updating the vulnerable Intel PROSet/Wireless WiFi software to version 23.80 or later.
Vulnerability scanning detects systems with vulnerable WiFi software versions and supports remediation to prevent exploitation.
Limits the effects of denial-of-service attacks triggered by the NULL pointer dereference in the WiFi software.