CVE-2026-20890
Summary
| CVE | CVE-2026-20890 |
|---|---|
| State | PUBLISHED |
| Assigner | intel |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-11 17:17:54 UTC |
| Updated | 2026-08-26 19:25:08 UTC |
| Description | Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (high) impacts. |
Risk And Classification
Primary CVSS: v4.0 7.1 HIGH from [email protected]
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.001240000 probability, percentile 0.023730000 (date 2026-08-26)
Problem Types: CWE-269 | Escalation of Privilege | CWE-269 Improper Privilege Management | CWE-269 CWE-269 Improper Privilege Management
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 7.1 | HIGH | CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 7.1 | HIGH | CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H |
| 3.1 | [email protected] | Primary | 7.3 | HIGH | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H |
CVSS v4.0 Breakdown
Attack Vector
LocalAttack Complexity
HighAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
LowIntegrity
LowAvailability
HighSub Conf.
LowSub Integrity
LowSub Availability
HighCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
LowIntegrity
LowAvailability
HighCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Intel | Killer Wi-fi 6e Ax1675i/s | - | All | All | All |
| Hardware | Intel | Killer Wi-fi 6e Ax1675x/w | - | All | All | All |
| Hardware | Intel | Killer Wi-fi 6 Ax1650i/s | - | All | All | All |
| Hardware | Intel | Killer Wi-fi 7 Be1750i/s | - | All | All | All |
| Hardware | Intel | Killer Wi-fi 7 Be1750x/w | - | All | All | All |
| Hardware | Intel | Killer Wi-fi 7 Be1775i/s | - | All | All | All |
| Application | Intel | Proset/wireless Wifi | All | All | All | All |
| Hardware | Intel | Wi-fi 6e Ax211 | - | All | All | All |
| Hardware | Intel | Wi-fi 6 Ax200 | - | All | All | All |
| Hardware | Intel | Wi-fi 6 Ax201 | - | All | All | All |
| Hardware | Intel | Wi-fi 6 Ax210 | - | All | All | All |
| Hardware | Intel | Wi-fi 7 Be200 | - | All | All | All |
| Hardware | Intel | Wi-fi 7 Be201 | - | All | All | All |
| Hardware | Intel | Wi-fi 7 Be211 | - | All | All | All |
| Hardware | Intel | Wi-fi 7 Be213 | - | All | All | All |
| Hardware | Intel | Wireless-ac 9461 | - | All | All | All |
| Hardware | Intel | Wireless-ac 9462 | - | All | All | All |
| Hardware | Intel | Wireless-ac 9560 | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | IntelR PROSet/Wireless WiFi Software For Windows | affected See references | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| intel.com/content/www/us/en/security-center/advisory/intel-sa-01468.html | [email protected] | intel.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.