Executive brief
Intel PROSet/Wireless WiFi Software is a driver and management suite for wireless network adapters on Windows systems. A null pointer dereference in the kernel-mode component can be triggered by an unauthenticated attacker over the network, causing the system to crash and become unavailable. This vulnerability requires no special privileges or user interaction, making it a straightforward avenue for attackers to cause service disruptions.
Technical details
CVE-2026-20727 is a null pointer dereference vulnerability in the Ring 0 kernel component of Intel PROSet/Wireless WiFi Software for Windows. The vulnerability can be triggered via an adjacent network attack (CVSS AV:A) by an unprivileged, unauthenticated adversary with low attack complexity and no special requirements. An attacker can send specially crafted network packets to exploit the null pointer dereference, causing a kernel panic or system crash, resulting in denial of service. The attack requires no user interaction. Patches are available from Intel; affected users should update to the latest version of PROSet/Wireless WiFi Software.
Affected products
- Intel PROSet/Wireless WiFi Software Windows versions prior to patched release (specific versions not disclosed in advisory)
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory: INTEL-SA-01468 released