Executive brief
Intel PROSet/Wireless WiFi Software includes device drivers that connect Windows computers to wireless networks. A network-based attacker can trigger an out-of-bounds memory write in these drivers without authentication, causing the system to crash or become unresponsive. The vulnerability requires the attacker to be on the same network segment (adjacent access) but no special privileges or user interaction.
Technical details
An out-of-bounds write vulnerability exists in the Ring 2 device drivers of Intel PROSet/Wireless WiFi Software for Windows (CVE-2026-20745). The flaw allows an unauthenticated network adversary with adjacent access to trigger a denial of service condition. Attack complexity is low and no user interaction is required. The vulnerability impacts system availability (high) and has minor integrity implications; confidentiality is not affected. Patches are available from Intel.
Affected products
- Intel PROSet/Wireless WiFi Software some versions for Windows
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory: INTEL-SA-01422