Help understanding Qubes Windows tools risk

I understand that the potentially compromised PV drivers are in a
qubes-tools-x64.msi package installed in a Windows VM. I read that there
were several RCEs and more vulnerabilities. So, if dom0 is not affected
(qsb91.txt), only the VM in which the potentially vulnerable driver is
installed is compromised? I really need to use QWT, so if I use the VM
without a netvm and then install the drivers, would there still be a
risk?

1 Like