CVE-2025-20090
Intel Quickassist Technology ≤ 2.5.0-0007
Raw vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSummary
CVE-2025-20090 is a medium-severity Untrusted Pointer Dereference (CWE-822) vulnerability in Intel Quickassist Technology. Its CVSS base score is 6.8 (Medium).
Operationally, ranked at the 3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) and SI-16 (Memory Protection) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-24435
Vulnerability Data
Untrusted Pointer Dereference for some Intel(R) QuickAssist Technology software before version 2.5.0 may allow an authenticated user to potentially enable denial of service via local access.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly requires validation of untrusted pointer inputs that the CVE exploits to cause dereference and DoS.
Enforces memory protection mechanisms that can block or contain untrusted pointer dereference attempts in the affected Intel QAT software.
Process isolation limits the blast radius of a local DoS triggered by the pointer dereference to the affected process only.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent introduction of untrusted pointer handling during development.
Runtime monitoring of software and data can detect adverse events resulting from exploitation of the weakness.
Vulnerability identification processes can discover instances of this weakness via code review or scanning.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing can detect pointer-dereference flaws before release.
Secure development lifecycle includes pointer-safety practices that reduce untrusted pointer dereference risk.
Application security requirements can mandate validation of pointers obtained from untrusted sources.
Secure architecture principles discourage direct use of untrusted values as pointers.
Secure coding standards explicitly forbid dereferencing pointers derived from untrusted input.