Junglewise Threat Intelligence

CVE-2026-20878: Intel PROSet/Wireless WiFi Software null pointer dereference

CVE-2026-20878 · Severity: high · CVSS 7.4 · Published 2026-08-11

Technologies: Intel Wi-Fi 7 Be211, Intel Wi-Fi 7 Be200, Intel Wireless Wifi, Intel Killer Wi-Fi 7 Be1775i\/S, Intel Wireless-Ac 9462, Intel Killer Wi-Fi 7 Be1750i\/S, Intel Wi-Fi 7 Be201, Intel Wi-Fi 7 Be213, Intel Killer Wi-Fi 6e Ax1675i\/S, Intel Proset\, Intel PROSet/Wireless WiFi Software, Intel Wi-Fi 6 Ax200, Intel Killer Wi-Fi 6e Ax1675x\/W, Intel Wireless-Ac 9560, Intel Wi-Fi 6e Ax211, Intel Killer Wi-Fi 6 Ax1650i\/S, Intel Wireless-Ac 9461, Intel Wi-Fi 6 Ax210, Intel Wi-Fi 6 Ax201, Intel Killer Wi-Fi 7 Be1750x\/W. Vendors: Intel.

Executive brief

Intel PROSet/Wireless WiFi Software is a driver package for Windows-based systems that manages wireless network connectivity. A null pointer dereference vulnerability in the Ring 2 device driver can be triggered remotely by an unauthenticated network adversary, causing the system to crash and become unavailable. This denial-of-service attack requires no user interaction and can be performed from an adjacent network.

Technical details

This is a null pointer dereference vulnerability in Intel PROSet/Wireless WiFi Software's Ring 2 device driver for Windows. The vulnerability is triggered via an adjacent network attack vector (AV:A) with low attack complexity (AC:L) and requires no user interaction or privilege escalation. An unauthenticated network adversary can send specially crafted packets to cause a null pointer dereference, resulting in a kernel-mode crash and denial of service. The vulnerability impacts system availability (VA:H) with minimal secondary impacts. Patches are expected from Intel's security advisory INTEL-SA-01422.

Affected products

  • Intel PROSet/Wireless WiFi Software affected versions unspecified

Timeline

  • 2026-08-11: disclosed: Published via NVD and Intel Security Advisory INTEL-SA-01422

References

Related threats