Junglewise Threat Intelligence

CVE-2026-20727: Intel PROSet/Wireless WiFi Software null pointer dereference denial of service

CVE-2026-20727 · Severity: high · CVSS 8.6 · Published 2026-08-11

Technologies: Intel Wi-Fi 7 Be211, Intel Wi-Fi 7 Be200, Intel Wireless Wifi, Intel Killer Wi-Fi 7 Be1775i\/S, Intel Wireless-Ac 9462, Intel Killer Wi-Fi 7 Be1750i\/S, Intel Wi-Fi 7 Be201, Intel Wi-Fi 7 Be213, Intel Killer Wi-Fi 6e Ax1675i\/S, Intel Proset\, Intel PROSet/Wireless WiFi Software, Intel Wi-Fi 6 Ax200, Intel Killer Wi-Fi 6e Ax1675x\/W, Intel Wireless-Ac 9560, Intel Wi-Fi 6e Ax211, Intel Killer Wi-Fi 6 Ax1650i\/S, Intel Wireless-Ac 9461, Intel Wi-Fi 6 Ax210, Intel Wi-Fi 6 Ax201, Intel Killer Wi-Fi 7 Be1750x\/W. Vendors: Intel.

Executive brief

Intel PROSet/Wireless WiFi Software is a driver and management suite for wireless network adapters on Windows systems. A null pointer dereference in the kernel-mode component can be triggered by an unauthenticated attacker over the network, causing the system to crash and become unavailable. This vulnerability requires no special privileges or user interaction, making it a straightforward avenue for attackers to cause service disruptions.

Technical details

CVE-2026-20727 is a null pointer dereference vulnerability in the Ring 0 kernel component of Intel PROSet/Wireless WiFi Software for Windows. The vulnerability can be triggered via an adjacent network attack (CVSS AV:A) by an unprivileged, unauthenticated adversary with low attack complexity and no special requirements. An attacker can send specially crafted network packets to exploit the null pointer dereference, causing a kernel panic or system crash, resulting in denial of service. The attack requires no user interaction. Patches are available from Intel; affected users should update to the latest version of PROSet/Wireless WiFi Software.

Affected products

  • Intel PROSet/Wireless WiFi Software Windows versions prior to patched release (specific versions not disclosed in advisory)

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory: INTEL-SA-01468 released

References

Related threats