Executive brief
Intel PROSet/Wireless WiFi Software is a driver and utility suite for wireless network adapters on Windows systems. A flaw in privilege management within the Ring 2 privileged process layer allows an unprivileged local attacker to escalate privileges to a higher access level, potentially compromising system security and data integrity. This vulnerability affects the confidentiality, integrity, and availability of the Windows system.
Technical details
CVE-2026-20890 is an improper privilege management vulnerability in Intel PROSet/Wireless WiFi Software for Windows, affecting Ring 2: Privileged Process components. The vulnerability requires local access and allows an unauthenticated unprivileged adversary to achieve privilege escalation with high attack complexity. No user interaction is required for exploitation. An attacker can leverage this flaw to gain elevated privileges, leading to potential impacts on system confidentiality (low), integrity (low), and availability (high). Intel has released software updates to mitigate this vulnerability.
Affected products
- Intel PROSet/Wireless WiFi Software some versions for Windows
Timeline
- 2026-08-11: disclosed: Initial advisory release
- 2026-09-22: other: Advisory last revised