← Browse

CVE-2026-20890

Medium

Elevated severity or exploit probability.

CVSS base
7.3 HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H
EPSS — probability of exploitation (30 days)
0.1%
2.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-269
Published 2026-08-11 · modified 2026-08-26

CVSS breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H

Attack VectorLLocal
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionNNone
ScopeCChanged
ConfidentialityLLow
IntegrityLLow
AvailabilityHHigh

Timeline

Description

Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (high) impacts.

Affected

intel

References

Official: NVD · CVE.org