Executive brief
Intel PROSet/Wireless WiFi Software is a driver package that manages WiFi connectivity on Windows systems. Multiple vulnerabilities in the Ring 2 device drivers allow unprivileged or network attackers to escalate privileges, execute arbitrary code, or cause denial of service without user interaction or authentication. These flaws could give attackers low-level control over affected systems or disrupt network connectivity.
Technical details
This advisory covers multiple vulnerability classes in Intel PROSet/Wireless WiFi Software Ring 2 device drivers, including improper access control (CVE-2026-20789, CVE-2026-20741), improper conditions checks (CVE-2026-20776, CVE-2026-20739), out-of-bounds read/write (CVE-2026-20749, CVE-2026-20745), and null pointer dereference (CVE-2026-20878). The primary vulnerability (CVE-2026-20737) involves exposure of sensitive information in the driver that may lead to privilege escalation via local access without authentication or special knowledge. Attack vectors include local (unprivileged process) and adjacent network (unauthenticated attacker) access, all with low complexity and no user interaction required. Successful exploitation can result in local code execution, denial of service, or information disclosure. Intel has released software updates to mitigate these vulnerabilities.
Affected products
- Intel PROSet/Wireless WiFi Software <UNKNOWN>
Timeline
- 2026-08-11: disclosed