Local Privilege Escalation in Colorful iGameCenter WinRing0x64.sys
Colorful iGameCenter 2.0.0.81 is vulnerable to local privilege escalation due to improper input validation within the WinRing0x64.sys IOCTL dispatch handler.
CVE search metadata
CVE search record: CVE-2026-82628. Severity: high. CVSS: 8.8. KEV: no. Product: iGameCenter (2.0.0.81). Brief: Local Privilege Escalation in Colorful iGameCenter WinRing0x64.sys. Brief link: https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82628/
A high-severity vulnerability (CVE-2026-82628) exists within the Colorful iGameCenter version 2.0.0.81 software suite. The flaw resides in the WinRing0x64.sys kernel-mode driver, specifically within the sub_11504 function responsible for handling IOCTL requests. An attacker with local access to the affected system can provide maliciously crafted arguments - specifically targeting the PhysicalAddress, AlignNumer, or AlignSize parameters - to trigger improper privilege management. Successful exploitation allows a local user to escalate privileges to the level of the kernel, potentially leading to full system compromise. As this vulnerability requires local access and interaction with the device driver interface, it primarily poses a threat to systems where low-privileged users can execute arbitrary code or interact with vulnerable hardware drivers.
Impact
Successful exploitation of this vulnerability results in local privilege escalation, allowing an attacker to execute arbitrary code with kernel-level permissions. This can lead to total system compromise, bypass of security controls, and persistent access that is difficult to detect or remove.
Recommendation
- Identify all systems running Colorful iGameCenter 2.0.0.81 in the environment using endpoint inventory tools.
- Restrict access to the WinRing0x64.sys driver interface if possible or remove/update the vulnerable version of the iGameCenter software suite.
- Monitor for unusual process creation or driver loading activity that may indicate an attempt to interact with third-party hardware drivers for privilege escalation.
Immediate actions
Inventory all endpoints running iGameCenter 2.0.0.81
Mitigations
Remove or update the vulnerable iGameCenter software
CVE-2026-82628