Executive brief
Intel PROSet/Wireless WiFi Software for Windows contains multiple security flaws in its Ring 2 device drivers that could allow unprivileged attackers to escalate privileges, execute arbitrary code, or crash systems without authentication or user interaction. Affected systems running vulnerable versions of this WiFi software driver are at risk of complete compromise via local or wireless network access, potentially exposing sensitive business data and disrupting operations.
Technical details
The advisory documents multiple vulnerabilities in Intel PROSet/Wireless WiFi Software Ring 2 drivers including improper authentication (CVE-2026-20891, CVE-2026-20789), improper access control (CVE-2026-20741), out-of-bounds read/write conditions (CVE-2026-20749, CVE-2026-20745), improper conditions checks (CVE-2026-20776, CVE-2026-20739), and null pointer dereference (CVE-2026-20878). Attack vectors include local access (unauthenticated, no user interaction required) and adjacent/network access via wireless. These vulnerabilities enable privilege escalation to Ring 0, local code execution, and denial of service. The flaws are in kernel-mode drivers with low attack complexity. Intel has released software updates to mitigate these issues.
Affected products
- Intel PROSet/Wireless WiFi Software <UNKNOWN>
Timeline
- 2026-08-11: disclosed