Sceawere

Vulnerability Detail

CVE-2026-19382UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Speedfan MSR Index Handler Memory Leak

Vulnerability Metadata

Severity
Low
Score / CVSS
2.3
Creation Date
6h ago
Vendor
Almico
Product
Speedfan
Attack Type
Memory Leak
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.3",
  "pubDate": "2026-08-10T01:16:48.537Z",
  "pubdate": "2026-08-10T01:16:48.537Z",
  "executiveSummary": "A local memory leak vulnerability has been identified in Almico Speedfan 4.52, specifically within the speedfan.sys driver component. The weakness resides in the KiSystemCall64 function of the MSR Index Handler, which improperly manages system memory resources during specific control requests. Successful exploitation of this vulnerability allows a locally authenticated attacker to induce a memory leak, potentially degrading system performance or destabilizing the operating system environment. The attack vector is restricted to local execution, requiring the adversary to possess execution privileges on the target host. Public exploits for this vulnerability have been released, increasing the risk of active exploitation. The vendor, Almico, was notified of the issue prior to public disclosure but failed to provide any response or official remediation patch. Consequently, organizations utilizing the affected software remain exposed unless compensating controls are implemented.",
  "technicalDetails": "The vulnerability is located in the kernel-mode driver file speedfan.sys, specifically within the KiSystemCall64 function associated with the MSR Index Handler component of Almico Speedfan 4.52. Kernel-mode drivers often expose IOCTL interfaces or callback routines that allow user-mode applications to interact with hardware-level Model-Specific Registers (MSRs). In this instance, improper validation, allocation, or deallocation of kernel memory pools during the processing of MSR index handling requests leads to a memory leak condition.\nFrom an exploitation perspective, the attack flow begins with a locally authenticated user launching a specially crafted application or script that interfaces with the vulnerable speedfan.sys driver. Because the driver runs with high privileges in kernel space, the user-mode process sends malicious or malformed input parameters to the driver's exposed communication interface. Specifically, the KiSystemCall64 function processes these inputs without adequately releasing previously allocated kernel structures or failing to reclaim memory blocks upon specific execution paths.\nAs the malicious payload is repeatedly executed, unreleased kernel memory accumulates, resulting in a persistent memory leak. While the primary immediate impact is the consumption of non-paged or paged pool memory, sustained exploitation can lead to resource exhaustion, system instability, and potential Denial of Service (DoS) conditions. The vulnerability requires local access and execution capabilities, meaning remote exploitation is not feasible unless combined with a separate remote code execution vector. Authentication requirements depend on the underlying Windows operating system security policy governing raw device or driver communication, but typically local standard user or administrative privileges are leveraged depending on how the driver ACLs are configured upon installation."
}
CVE-2026-19382: Speedfan MSR Index Handler Memory Leak (LOW Severity, CVSS: 2.3) - Sceawere