Junglewise Threat Intelligence

CVE-2026-20749: Intel PROSet/Wireless WiFi Software out-of-bounds read in device drivers

CVE-2026-20749 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: Intel Wireless Wifi, Intel Killer Wi-Fi 7 Be1750i\/S, Intel Proset\, Intel Wireless-Ac 9560, Intel Wi-Fi 6 Ax210, Intel Killer Wi-Fi 6 Ax1650i\/S, Intel PROSet/Wireless WiFi Software, Intel Wi-Fi 6e Ax211, Intel Killer Wi-Fi 7 Be1750x\/W, Intel Killer Wi-Fi 6e Ax1675x\/W, Intel Wi-Fi 6 Ax201, Intel Killer Wi-Fi 6e Ax1675i\/S, Intel Wi-Fi 7 Be211, Intel Wi-Fi 7 Be200, Intel Wireless-Ac 9461, Intel Wi-Fi 7 Be213, Intel Wi-Fi 7 Be201, Intel Wi-Fi 6 Ax200, Intel Killer Wi-Fi 7 Be1775i\/S, Intel Wireless-Ac 9462. Vendors: Intel.

Executive brief

Intel PROSet/Wireless WiFi Software is driver software that manages wireless network connectivity on Windows systems. A network-accessible vulnerability in the Ring 2 device drivers allows an unauthenticated adjacent network attacker to crash the system or escalate privileges without user interaction, potentially compromising system confidentiality, integrity, and availability.

Technical details

An out-of-bounds read vulnerability exists in Intel PROSet/Wireless WiFi Software's Ring 2 device drivers, which operate with elevated kernel privileges. The flaw can be triggered by a network adversary with adjacent access (e.g., on the same wireless network) without authentication or user interaction, as attack complexity is low. Exploitation can result in escalation of privilege and impacts to system confidentiality and availability. Intel has released software updates to mitigate this issue as of August 2026.

Affected products

  • Intel PROSet/Wireless WiFi Software unspecified

Timeline

  • 2026-08-11: disclosed

References

Related threats