CVE-2025-35971
8.2Intel · PROSet/Wireless WiFi Software
An out-of-bounds write vulnerability in Intel PROSet/Wireless WiFi Software for Windows allows an unauthenticated, adjacent attacker to cause a denial of service.
Executive summary
A critical out-of-bounds write vulnerability in Intel PROSet/Wireless WiFi Software enables unauthenticated attackers to trigger a denial of service on affected Windows systems.
Vulnerability
This flaw is an out-of-bounds write (CWE-787) occurring within Ring 2 device drivers. It can be exploited by an unauthenticated attacker with adjacent network access to cause a system denial of service.
Business impact
The ability to trigger a denial of service against network-dependent components poses a significant risk to operational continuity. Because the vulnerability allows for high availability impact, a successful exploit could render wireless connectivity unusable for critical business functions. With a CVSS score of 8.2, this vulnerability is categorized as High, necessitating prompt attention to prevent service disruptions.
Remediation
Immediate Action: Update all instances of Intel PROSet/Wireless WiFi Software for Windows to version 23.160 or later.
Proactive Monitoring: Monitor system event logs for unusual driver crashes or recurring wireless connectivity failures that may indicate exploitation attempts.
Compensating Controls: Ensure that network access control policies are strictly enforced to limit the exposure of wireless management interfaces to untrusted adjacent users.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for service interruption, organizations should prioritize updating the Intel wireless drivers across their Windows fleet. While no active exploitation is confirmed, the nature of driver-level vulnerabilities often makes them attractive targets for localized disruption, and applying the vendor-supplied update is the only definitive way to resolve this issue.