Sceawere
Vulnerability Detail
CVE-2026-82628UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Improper Privilege Management in WinRing0x64.sys
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 23h ago
- Vendor
- Colorful
- Product
- iGameCenter
- Attack Type
- Improper Privilege Management
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-31T07:17:47.307Z",
"pubdate": "2026-08-31T07:17:47.307Z",
"executiveSummary": "A vulnerability has been identified in the WinRing0x64.sys library used by Colorful iGameCenter 2.0.0.81, specifically residing within the IOCTL dispatch routine.\nThe vulnerability is classified as improper privilege management, stemming from insufficient validation of user-supplied input provided via IOCTL requests.\nThis flaw allows a local, authenticated attacker to interact with the kernel-mode driver, potentially leading to unauthorized privilege escalation or system instability.\nThe vulnerability requires local access to the affected system, as the IOCTL interface is reachable from the user-mode environment.\nThe risk implication is significant due to the nature of WinRing0x64.sys, which is a third-party driver frequently associated with hardware-level access, meaning successful exploitation grants the attacker kernel-level execution privileges.\nThe primary requirement for exploitation is local execution context on the target host.",
"technicalDetails": "The vulnerability is located within the IOCTL Dispatch routine of WinRing0x64.sys, specifically impacting the function sub_11504. The root cause is the failure of the driver to properly sanitize and validate the input parameters passed through the IOCTL interface.\nThe dispatch function sub_11504 accepts user-controlled arguments, namely PhysicalAddress, AlignNumer, and AlignSize. When these arguments are processed by the kernel driver, the absence of robust bound-checking or validation logic leads to an improper privilege management scenario.\nThe attack flow begins with a local attacker identifying the device object associated with the WinRing0x64.sys driver. Using the CreateFile API, the attacker gains a handle to the device. Once connected, the attacker sends a crafted DeviceIoControl request to the driver, specifically targeting the IOCTL code handled by sub_11504.\nBy supplying malicious or non-standard values for PhysicalAddress, AlignNumer, and AlignSize, the attacker can force the kernel driver to perform unauthorized memory operations or reference memory regions that should be inaccessible from user mode.\nBecause the operation is performed within the context of the kernel-mode driver, it bypasses standard Windows access controls. Improper validation of the PhysicalAddress allows the attacker to read from or write to kernel memory locations, which can be leveraged to overwrite sensitive kernel structures, such as the process token or function pointers in the System Service Descriptor Table (SSDT).\nFollowing the initial memory manipulation, an attacker can redirect execution flow to a payload crafted to elevate the privileges of their user-mode process to NT AUTHORITY\\SYSTEM. The exploitation does not require network exposure, as it relies on the direct interaction between a local user-mode application and the kernel-mode driver via the Windows I/O Manager.\nPost-exploitation, the attacker achieves persistent kernel-level execution, effectively bypassing all OS security boundaries on the host machine. This grants the capability to disable security software, install rootkits, or exfiltrate sensitive data directly from kernel memory."
}