Junglewise Threat Intelligence

CVE-2026-20890: Intel PROSet/Wireless WiFi Software privilege escalation in Ring 2

CVE-2026-20890 · Severity: high · CVSS 7.3 · Published 2026-08-11

Technologies: Intel Wi-Fi 7 Be211, Intel Wi-Fi 7 Be200, Intel Wireless Wifi, Intel Killer Wi-Fi 7 Be1775i\/S, Intel Wireless-Ac 9462, Intel Killer Wi-Fi 7 Be1750i\/S, Intel Wi-Fi 7 Be201, Intel Wi-Fi 7 Be213, Intel Killer Wi-Fi 6e Ax1675i\/S, Intel Proset\, Intel PROSet/Wireless WiFi Software, Intel Wi-Fi 6 Ax200, Intel Killer Wi-Fi 6e Ax1675x\/W, Intel Wireless-Ac 9560, Intel Wi-Fi 6e Ax211, Intel Killer Wi-Fi 6 Ax1650i\/S, Intel Wireless-Ac 9461, Intel Wi-Fi 6 Ax210, Intel Wi-Fi 6 Ax201, Intel Killer Wi-Fi 7 Be1750x\/W. Vendors: Intel.

Executive brief

Intel PROSet/Wireless WiFi Software is a driver and utility suite for wireless network adapters on Windows systems. A flaw in privilege management within the Ring 2 privileged process layer allows an unprivileged local attacker to escalate privileges to a higher access level, potentially compromising system security and data integrity. This vulnerability affects the confidentiality, integrity, and availability of the Windows system.

Technical details

CVE-2026-20890 is an improper privilege management vulnerability in Intel PROSet/Wireless WiFi Software for Windows, affecting Ring 2: Privileged Process components. The vulnerability requires local access and allows an unauthenticated unprivileged adversary to achieve privilege escalation with high attack complexity. No user interaction is required for exploitation. An attacker can leverage this flaw to gain elevated privileges, leading to potential impacts on system confidentiality (low), integrity (low), and availability (high). Intel has released software updates to mitigate this vulnerability.

Affected products

  • Intel PROSet/Wireless WiFi Software some versions for Windows

Timeline

  • 2026-08-11: disclosed: Initial advisory release
  • 2026-09-22: other: Advisory last revised

References

Related threats