Executive brief
Intel's wireless WiFi driver software for Windows contains an out-of-bounds memory read vulnerability in the kernel driver (Ring 0). An unprivileged attacker on a nearby network can exploit this flaw without authentication to cause a system crash, disrupting operations and availability. The vulnerability requires specific conditions and high attack complexity but poses a real risk to systems using affected Intel wireless drivers.
Technical details
CVE-2026-20778 is an out-of-bounds read vulnerability in Intel PROSet/Wireless WiFi Software's Ring 0 kernel driver. The flaw can be exploited by an unauthenticated, unprivileged attacker via adjacent network access under specific conditions. The attack requires high complexity and the presence of particular attack prerequisites, but requires no user interaction. Exploitation leads to denial of service through system crash or instability. No information disclosure or integrity compromise occurs. Patches are available from Intel as part of INTEL-SA-01468 advisory released August 11, 2026.
Affected products
- Intel PROSet/Wireless WiFi Software unspecified
Timeline
- 2026-08-11: disclosed
- 2026-09-22: advisory: Last revised INTEL-SA-01468