Junglewise Threat Intelligence

CVE-2026-24099: Intel PROSet/Wireless WiFi Software use-after-free in kernel

CVE-2026-24099 · Severity: medium · CVSS 5.1 · Published 2026-08-11

Technologies: Intel Wi-Fi 7 Be211, Intel Wi-Fi 7 Be200, Intel Wireless Wifi, Intel Killer Wi-Fi 7 Be1775i\/S, Intel Wireless-Ac 9462, Intel Killer Wi-Fi 7 Be1750i\/S, Intel Wi-Fi 7 Be201, Intel Wi-Fi 7 Be213, Intel Killer Wi-Fi 6e Ax1675i\/S, Intel Proset\, Intel PROSet/Wireless WiFi Software, Intel Wi-Fi 6 Ax200, Intel Killer Wi-Fi 6e Ax1675x\/W, Intel Wireless-Ac 9560, Intel Wi-Fi 6e Ax211, Intel Killer Wi-Fi 6 Ax1650i\/S, Intel Wireless-Ac 9461, Intel Wi-Fi 6 Ax210, Intel Wi-Fi 6 Ax201, Intel Killer Wi-Fi 7 Be1750x\/W. Vendors: Intel.

Executive brief

Intel PROSet/Wireless WiFi Software is a system driver that manages wireless network connectivity on Windows. A use-after-free vulnerability in the kernel driver (Ring 0) can allow a local attacker with system software privileges to crash the system, resulting in denial of service. An attacker may exploit this without requiring user interaction to disrupt normal operations.

Technical details

The vulnerability is a use-after-free memory safety issue in the Intel PROSet/Wireless WiFi Software kernel driver (Ring 0 context). The attack vector is local access, and exploitation requires system software adversary privileges combined with an unauthenticated user and high attack complexity. An attacker can trigger the use-after-free to crash the system or potentially cause undefined behavior. The vulnerability impacts availability only (no confidentiality or integrity impact). Patches are available through Intel security advisory INTEL-SA-01468.

Affected products

  • Intel PROSet/Wireless WiFi Software

Timeline

  • 2026-08-11: disclosed
  • 2026-09-22: advisory: Last revised by Intel

References

Related threats