Researchers: security flaws in 40+ kernel drivers from 20 vendors including Intel, AMD, and Huawei, can give hackers improperly elevated privileges on Windows
Affected vendors include the likes of Intel, AMD, NVIDIA, ASRock, AMI, Gigabyte, Realtek, Huawei, and more.
Context & Ripple Effects
This disclosure extends a decade-long pattern of researchers finding that the lowest layers of the PC stack are the least defended. The lineage runs from an almost three-year-old privilege escalation bug in the Linux kernel, through the 2018 Meltdown and Spectre chip vulnerabilities, to the firmware flaws that sent PC vendors scrambling to patch millions of devices.
What is new here is the target: not chips or OS kernels themselves but third-party kernel drivers from 20 vendors at once — Intel, AMD, NVIDIA, Huawei, Gigabyte, ASRock, AMI, Realtek among them — meaning the attack surface is fragmented across companies with very different security maturity.
First-order effects
- Twenty vendors must ship fixed drivers for 40+ components, while any Windows user running an unpatched driver — from GPUs to motherboards to audio chips — is exposed to local privilege escalation until their specific vendor acts.
- The burden falls unevenly: Intel and AMD have dedicated security teams, but smaller suppliers like Realtek, ASRock, and AMI now face coordinated disclosure timelines they may be slower to meet.
Second-order effects
- Microsoft comes under pressure to tighten driver signing and certification requirements, because a signed driver is currently a trust passport into the kernel regardless of code quality — echoing how the documentation misinterpretation that hit Windows, macOS, and Linux alike forced OS vendors to treat low-level code as a shared problem.
- Enterprise IT teams gain a new audit requirement: inventorying and updating kernel drivers across fleets, a task most organizations handle only during hardware refreshes.
Third-order effects
- If the pattern holds, kernel drivers become treated as supply-chain attack surface in their own right, pushing OS vendors toward stricter attestation regimes and shifting compliance costs onto peripheral and motherboard makers who historically shipped drivers as an afterthought.
- A fragmented ecosystem of 20 vendors each patching on its own cadence strengthens the case for centralized enforcement — the same dynamic that followed Meltdown/Spectre, where mitigation had to be coordinated across chipmakers, OS vendors, and device makers simultaneously.
The trend: PC security accountability keeps moving down the stack — from applications to OS kernels to chips to now third-party drivers — forcing every vendor with kernel-signed code into the disclosure-and-patch cycle.