Junglewise Threat Intelligence

CVE-2026-20752: Intel PROSet/Wireless WiFi Software improper authentication information disclosure

CVE-2026-20752 · Severity: medium · CVSS 4.4 · Published 2026-08-11

Technologies: Intel Wi-Fi 7 Be211, Intel Wi-Fi 7 Be200, Intel Wireless Wifi, Intel Killer Wi-Fi 7 Be1775i\/S, Intel Wireless-Ac 9462, Intel Killer Wi-Fi 7 Be1750i\/S, Intel Wi-Fi 7 Be201, Intel Wi-Fi 7 Be213, Intel Killer Wi-Fi 6e Ax1675i\/S, Intel Proset\, Intel PROSet/Wireless WiFi Software, Intel Wi-Fi 6 Ax200, Intel Killer Wi-Fi 6e Ax1675x\/W, Intel Wireless-Ac 9560, Intel Wi-Fi 6e Ax211, Intel Killer Wi-Fi 6 Ax1650i\/S, Intel Wireless-Ac 9461, Intel Wi-Fi 6 Ax210, Intel Wi-Fi 6 Ax201, Intel Killer Wi-Fi 7 Be1750x\/W. Vendors: Intel.

Executive brief

Intel's PROSet/Wireless WiFi Software is a wireless network driver and management tool used in business and consumer systems. A privileged user can exploit an authentication weakness in the kernel-mode driver to read sensitive data from system memory, potentially exposing passwords, encryption keys, or other confidential information. This vulnerability requires local system access and elevated privileges to exploit.

Technical details

CVE-2026-20752 is an improper authentication vulnerability in Intel PROSet/Wireless WiFi Software's kernel-mode (Ring 0) driver. The vulnerability allows an attacker with privileged user access to bypass authentication controls and disclose sensitive information from kernel memory via local access. The attack has low complexity and requires no user interaction. The vulnerability impacts confidentiality only; integrity and availability are not affected. Intel rates this as CVSS 6.7 (Medium) with vector AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N.

Affected products

  • Intel PROSet/Wireless WiFi Software

Timeline

  • 2026-08-11: disclosed
  • 2026-09-22: advisory: Last revised

References

Related threats