Sceawere

Vulnerability Detail

CVE-2026-19381UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kingston FURY CTRL Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
6h ago
Vendor
Kingston
Product
FURY CTRL RGB Control Software
Attack Type
Improper Privilege Management
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-10T01:16:48.367Z",
  "pubdate": "2026-08-10T01:16:48.367Z",
  "executiveSummary": "A security flaw involving improper privilege management has been identified within the Kingston FURY CTRL RGB Control Software version 2.0.65.0. The vulnerability resides in the Driver component, specifically within the library file NTIOLib_KSFX.sys, affecting an unspecified internal function.\nThe primary impact of this vulnerability is unauthorized privilege escalation, allowing a local attacker to manipulate the system and potentially execute arbitrary code or commands with elevated privileges.\nThe affected product is Kingston FURY CTRL RGB Control Software 2.0.65.0. Risk implications are significant because an exploit has been publicly released and is available for malicious actors to leverage in active attacks. The vendor was contacted early regarding the disclosure but failed to provide any response or official patch.\nExploitation requirements dictate that the attacker must have local access to the target system to interact with the vulnerable driver interface. Since the attack vector is strictly local, remote exploitation is not natively supported by this specific flaw.",
  "technicalDetails": "The vulnerability stems from improper privilege management implemented within the driver architecture of Kingston FURY CTRL RGB Control Software 2.0.65.0. Specifically, the flaw exists in the NTIOLib_KSFX.sys driver component, which exposes exposed Input/Output Control (IOCTL) interfaces or insecure communication channels to user-mode applications without adequate access validation.\nThe root cause is an oversight in how the driver handles requests from low-privileged user-mode processes. Because the driver executes with kernel-level privileges (Ring 0), failure to properly sanitize, validate, or restrict incoming requests allows local user-mode applications to interact with kernel memory or hardware resources in an unintended manner.\nThe attack flow proceeds locally through the following sequence: First, an authenticated or unprivileged attacker gains local execution access on the target host system. Second, the attacker executes a publicly available exploit payload designed to interface with the NTIOLib_KSFX.sys driver. Third, by sending specially crafted input parameters or malicious IOCTL requests to the driver, the attacker bypasses standard Windows access controls. Finally, the improper privilege management logic permits the execution of arbitrary actions within the kernel space, leading to local privilege escalation.\nAuthentication and privilege requirements for initial exploitation are minimal, requiring only standard local user execution capabilities to interact with the exposed device driver. Network exposure is non-existent, as the vulnerability cannot be reached across a network boundary without prior local access or a separate remote code execution vector. Post-exploitation impact typically includes complete compromise of the underlying operating system, as successful exploitation of kernel-mode drivers commonly yields SYSTEM-level privileges, enabling defense evasion, persistence establishment, and unrestricted resource access."
}
CVE-2026-19381: Kingston FURY CTRL Privilege Escalation (HIGH Severity, CVSS: 7.8) - Sceawere