Junglewise Threat Intelligence

CVE-2026-20795: Intel PROSet/Wireless WiFi Software buffer restriction denial of service

CVE-2026-20795 · Severity: high · CVSS 7.4 · Published 2026-08-11

Technologies: Intel Wi-Fi 7 Be211, Intel Wi-Fi 7 Be200, Intel Wireless Wifi, Intel Killer Wi-Fi 7 Be1775i\/S, Intel Wireless-Ac 9462, Intel Killer Wi-Fi 7 Be1750i\/S, Intel Wi-Fi 7 Be201, Intel Wi-Fi 7 Be213, Intel Killer Wi-Fi 6e Ax1675i\/S, Intel Proset\, Intel PROSet/Wireless WiFi Software, Intel Wi-Fi 6 Ax200, Intel Killer Wi-Fi 6e Ax1675x\/W, Intel Wireless-Ac 9560, Intel Wi-Fi 6e Ax211, Intel Killer Wi-Fi 6 Ax1650i\/S, Intel Wireless-Ac 9461, Intel Wi-Fi 6 Ax210, Intel Wi-Fi 6 Ax201, Intel Killer Wi-Fi 7 Be1750x\/W. Vendors: Intel.

Executive brief

Intel PROSet/Wireless WiFi Software for Windows contains improper buffer handling in its Ring 2 device drivers that can be exploited by network-based attackers to disrupt system availability. An attacker on the same network can send specially crafted packets to crash or hang the affected system without needing authentication or user interaction, resulting in temporary service outages or system downtime.

Technical details

CVE-2026-20795 involves improper buffer restrictions in Intel PROSet/Wireless WiFi Software Ring 2 device drivers for Windows. The vulnerability allows a network-adjacent, unauthenticated attacker to trigger a denial of service condition via crafted network traffic. Low attack complexity and no user interaction is required. The affected driver code does not properly validate buffer boundaries before processing incoming wireless frames, allowing an attacker on the same network segment to cause a system crash or hang. Intel has released firmware and driver updates to address this and related vulnerabilities in the advisory INTEL-SA-01422.

Affected products

  • Intel PROSet/Wireless WiFi Software <UNKNOWN>

Timeline

  • 2026-08-11: disclosed
  • 2026-08-11: advisory: INTEL-SA-01422

References

Related threats