Executive brief
Intel's PROSet/Wireless WiFi Software for Windows contains a memory safety vulnerability in its Ring 2 device driver that allows a network attacker to cause system instability or crashes. An attacker on the local network can trigger this vulnerability without authentication or user interaction, leading to denial of service that impacts system availability and potentially causes data loss or downtime.
Technical details
CVE-2026-20886 is an out-of-bounds write vulnerability in Intel PROSet/Wireless WiFi Software's Ring 2 device driver for Windows. The flaw exists in the wireless driver's packet processing logic, allowing adjacent network attackers to send specially crafted WiFi frames that trigger the out-of-bounds memory write. The attack requires no authentication, no special privileges, and no user interaction, making it exploitable by any device on the local network segment. Successful exploitation results in denial of service through system crash or instability; the vulnerability has low potential impact on data integrity and confidentiality. Intel has released software updates to patch this and related vulnerabilities in the PROSet/Wireless WiFi Software suite.
Affected products
- Intel PROSet/Wireless WiFi Software for Windows unspecified
Timeline
- 2026-08-11: disclosed