Executive brief
Intel's PROSet/Wireless WiFi Software is a wireless network driver and management tool used in business and consumer systems. A privileged user can exploit an authentication weakness in the kernel-mode driver to read sensitive data from system memory, potentially exposing passwords, encryption keys, or other confidential information. This vulnerability requires local system access and elevated privileges to exploit.
Technical details
CVE-2026-20752 is an improper authentication vulnerability in Intel PROSet/Wireless WiFi Software's kernel-mode (Ring 0) driver. The vulnerability allows an attacker with privileged user access to bypass authentication controls and disclose sensitive information from kernel memory via local access. The attack has low complexity and requires no user interaction. The vulnerability impacts confidentiality only; integrity and availability are not affected. Intel rates this as CVSS 6.7 (Medium) with vector AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N.
Affected products
- Intel PROSet/Wireless WiFi Software
Timeline
- 2026-08-11: disclosed
- 2026-09-22: advisory: Last revised