Junglewise Threat Intelligence

CVE-2026-20778: Intel PROSet/Wireless WiFi Software out-of-bounds read denial of service

CVE-2026-20778 · Severity: medium · CVSS 6.8 · Published 2026-08-11

Technologies: Intel Wi-Fi 7 Be211, Intel Wi-Fi 7 Be200, Intel Wireless Wifi, Intel Killer Wi-Fi 7 Be1775i\/S, Intel Wireless-Ac 9462, Intel Killer Wi-Fi 7 Be1750i\/S, Intel Wi-Fi 7 Be201, Intel Wi-Fi 7 Be213, Intel Killer Wi-Fi 6e Ax1675i\/S, Intel Proset\, Intel PROSet/Wireless WiFi Software, Intel Wi-Fi 6 Ax200, Intel Killer Wi-Fi 6e Ax1675x\/W, Intel Wireless-Ac 9560, Intel Wi-Fi 6e Ax211, Intel Killer Wi-Fi 6 Ax1650i\/S, Intel Wireless-Ac 9461, Intel Wi-Fi 6 Ax210, Intel Wi-Fi 6 Ax201, Intel Killer Wi-Fi 7 Be1750x\/W. Vendors: Intel.

Executive brief

Intel's wireless WiFi driver software for Windows contains an out-of-bounds memory read vulnerability in the kernel driver (Ring 0). An unprivileged attacker on a nearby network can exploit this flaw without authentication to cause a system crash, disrupting operations and availability. The vulnerability requires specific conditions and high attack complexity but poses a real risk to systems using affected Intel wireless drivers.

Technical details

CVE-2026-20778 is an out-of-bounds read vulnerability in Intel PROSet/Wireless WiFi Software's Ring 0 kernel driver. The flaw can be exploited by an unauthenticated, unprivileged attacker via adjacent network access under specific conditions. The attack requires high complexity and the presence of particular attack prerequisites, but requires no user interaction. Exploitation leads to denial of service through system crash or instability. No information disclosure or integrity compromise occurs. Patches are available from Intel as part of INTEL-SA-01468 advisory released August 11, 2026.

Affected products

  • Intel PROSet/Wireless WiFi Software unspecified

Timeline

  • 2026-08-11: disclosed
  • 2026-09-22: advisory: Last revised INTEL-SA-01468

References

Related threats