Hi Steve,
thank you for your quick reply and the hint regarding registry.
However i couldn't identify potentially unsuitable registry settings within reasonable time, so instead i did a counter-check by importing the very same PFX file into Windows' certificate store.
I had to grant read permissions to "NETWORK SERVICE" for the imported private key, but this way the intermediate CA certificate is served to the clients properly.
Interestingly when switching back to the PFX file in ProGet's config afterwards (+ service restart), clients still receive the intermediate CA certificate. Only after deleting the intermediate CA certificate from Windows' certificate store, ProGet starts complaining about "Error PartialChain: A certificate chain could not be built to a trusted root authority." (root CA certificate is available in Windows' certificate store all the time).
This makes me think, that the current implementation doesn't read intermediate CA certificates from PFX files.