Executive brief
Intel PROSet/Wireless WiFi Software for Windows contains improper buffer handling in its Ring 2 device drivers that can be exploited by network-based attackers to disrupt system availability. An attacker on the same network can send specially crafted packets to crash or hang the affected system without needing authentication or user interaction, resulting in temporary service outages or system downtime.
Technical details
CVE-2026-20795 involves improper buffer restrictions in Intel PROSet/Wireless WiFi Software Ring 2 device drivers for Windows. The vulnerability allows a network-adjacent, unauthenticated attacker to trigger a denial of service condition via crafted network traffic. Low attack complexity and no user interaction is required. The affected driver code does not properly validate buffer boundaries before processing incoming wireless frames, allowing an attacker on the same network segment to cause a system crash or hang. Intel has released firmware and driver updates to address this and related vulnerabilities in the advisory INTEL-SA-01422.
Affected products
- Intel PROSet/Wireless WiFi Software <UNKNOWN>
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory: INTEL-SA-01422