CVE-2026-20737
Awaiting Analysis Awaiting Analysis - Queue

Exposure of Sensitive Information in Intel PROSet/Wireless WiFi Software

Vulnerability report for CVE-2026-20737, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Intel Corporation

Description

Exposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (low) and availability (low) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-11
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
intel proset_wireless_wifi_software *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves exposure of sensitive information in Intel PROSet/Wireless WiFi Software for Windows. An unauthenticated attacker with local access could exploit it to escalate privileges and execute local code without special knowledge or user interaction. The attack has low complexity and could impact system confidentiality, integrity, and availability.

Detection Guidance

This CVE involves Intel PROSet/Wireless WiFi Software for Windows. Detection requires checking installed versions of the software and verifying if updates are applied. Use system tools like 'wmic product get name' or 'Get-WmiObject -Class Win32_Product' to list installed software. Compare versions against Intel's advisory for CVE-2026-20737.

Impact Analysis

An attacker could gain unauthorized access to sensitive data on your system, potentially leading to further compromise. They might execute malicious code locally, which could allow them to take control of your device or steal information. The impact includes high confidentiality loss and potential low integrity and availability issues.

Compliance Impact

The vulnerability may lead to unauthorized access to sensitive information, which could violate confidentiality requirements in standards like GDPR and HIPAA. Unauthorized local code execution could further compromise data integrity and availability, potentially resulting in non-compliance with these regulations.

Mitigation Strategies

Update Intel PROSet/Wireless WiFi Software for Windows to the latest version provided by Intel to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20737. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart