Description
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow an escalation of privilege. Network adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (low) impacts.
Published: 2026-08-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Intel® PROSet/Wireless WiFi Software contains an out‑of‑bounds read within a ring‑2 device driver. The flaw enables a network adversary to gain elevated privileges with an unauthenticated connection, employing a low‑complexity attack that does not require user interaction. The read could expose process memory, leading to a modest breach of confidentiality and integrity, but the larger threat is the potential to disrupt services, resulting in high availability impact.

Affected Systems

The vulnerability affects the Intel® PROSet/Wireless WiFi Software driver stack. No specific product versions are listed, so all installations of this driver must be treated as potentially vulnerable until an update is applied.

Risk and Exploitability

The CVSS score of 7.2 combined with an EPSS score of less than 1% indicates moderate overall risk. The flaw is exposed over the network from unauthenticated hosts and can be triggered by adjacent access without special internal knowledge. Although the vulnerability is not listed in CISA KEV, the high availability impact warrants vigilance and prompt mitigation.

Generated by OpenCVE AI on August 12, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Intel® PROSet/Wireless WiFi Software update that addresses the out‑of‑bounds read in the driver.
  • If an update is not yet available, disable the Wi‑Fi interface or restrict the wireless network to trusted hosts only.
  • Configure network segmentation or firewall rules to block adjacent hosts from reaching the affected system, limiting the attack surface.

Generated by OpenCVE AI on August 12, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel proset/wireless Software
Vendors & Products Intel
Intel proset/wireless Software

Wed, 12 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Intel PROSet/Wireless WiFi Software Allowing Privilege Escalation

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow an escalation of privilege. Network adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (low) impacts.
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

Intel Proset/wireless Software
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:48:49.293Z

Reserved: 2025-12-03T18:04:52.995Z

Link: CVE-2026-20749

cve-icon Vulnrichment

Updated: 2026-08-12T15:48:43.766Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:51.293

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-20749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses