CVE-2026-22887
Intel PROSet/Wireless WiFi Software vulnerability analysis and mitigation

Overview

CVE-2026-22887 is an improper buffer restriction vulnerability in Intel PROSet/Wireless WiFi Software for Windows affecting the Ring 0 (Kernel) layer, which may allow a denial of service. The vulnerability affects all versions of Intel PROSet/Wireless WiFi Software prior to 24.10.0. It was disclosed by Intel on August 11, 2026, via security advisory INTEL-SA-01468. The vulnerability carries a CVSS v3.1 base score of 7.4 (High) and a CVSS v4.0 base score of 8.3 (High) (Intel Advisory).

Technical details

The vulnerability is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), stemming from insufficient buffer boundary enforcement within the kernel-mode WiFi driver component. An unauthenticated attacker on an adjacent network can exploit this flaw with low attack complexity and no user interaction required, by sending specially crafted network traffic that triggers improper buffer handling in the Ring 0 kernel driver. No special internal knowledge or elevated privileges are required to trigger the vulnerability. No public proof-of-concept or technical write-up has been identified at this time (Intel Advisory).

Impact

Successful exploitation of this vulnerability primarily impacts availability, with a high availability impact at both the vulnerable system and subsequent system levels, potentially causing a kernel-level denial of service (e.g., system crash or blue screen). Integrity impact is rated low at the vulnerable system level, while confidentiality is not affected. Because the flaw resides in the kernel (Ring 0), a triggered crash could affect the entire host system rather than just the WiFi software process (Intel Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit for CVE-2026-22887. The EPSS score is approximately 0.172%, indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Intel Advisory).

Mitigation and workarounds

Intel has released a patched version of PROSet/Wireless WiFi Software for Windows (version 24.10.0 or later) that addresses this vulnerability. Organizations should update all affected systems to version 24.10.0 or newer as the primary remediation step. Until patching is feasible, consider restricting adjacent network access to affected systems or disabling the Intel WiFi adapter on sensitive hosts where wireless connectivity is not required. Refer to INTEL-SA-01468 for the official software update and additional guidance (Intel Advisory).

Community reactions

HP has published a support document referencing this vulnerability in the context of affected HP systems, indicating downstream vendor acknowledgment of the issue. No significant researcher commentary or broad media coverage has been identified beyond the initial Intel advisory disclosure (Intel Advisory).

Additional resources


SourceThis report was generated using AI

Related Intel PROSet/Wireless WiFi Software vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24911HIGH8.3
  • Intel PROSet/Wireless WiFi Software logoIntel PROSet/Wireless WiFi Software
  • cpe:2.3:a:intel:proset\/wireless_wifi
NoYesAug 11, 2026
CVE-2026-22887HIGH8.3
  • Intel PROSet/Wireless WiFi Software logoIntel PROSet/Wireless WiFi Software
  • cpe:2.3:a:intel:proset\/wireless_wifi
NoYesAug 11, 2026
CVE-2026-20890HIGH7.1
  • Intel PROSet/Wireless WiFi Software logoIntel PROSet/Wireless WiFi Software
  • cpe:2.3:a:intel:proset\/wireless_wifi
NoYesAug 11, 2026
CVE-2026-20891MEDIUM6.3
  • Intel PROSet/Wireless WiFi Software logoIntel PROSet/Wireless WiFi Software
  • cpe:2.3:a:intel:proset\/wireless_wifi
NoYesAug 11, 2026
CVE-2026-24099MEDIUM5.9
  • Intel PROSet/Wireless WiFi Software logoIntel PROSet/Wireless WiFi Software
  • cpe:2.3:a:intel:proset\/wireless_wifi
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management