{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/fury-ctrl-rgb-control-software-2.0.65.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-19381"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FURY CTRL RGB Control Software (2.0.65.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","windows","driver-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Kingston"],"content_html":"\u003cp\u003eA security vulnerability has been identified in Kingston FURY CTRL RGB Control Software version 2.0.65.0. The vulnerability resides within the NTIOLib_KSFX.sys driver component and is classified as an improper privilege management issue. An attacker with local access to the system can leverage this flaw to elevate privileges. Public exploit code for this vulnerability has been released, increasing the risk of exploitation by local threat actors or malware already residing on a host. Despite early notification, the vendor has not provided a patch or a response to the disclosure, leaving systems running this software exposed to potential local privilege escalation (LPE) attacks. This is particularly relevant to defenders as drivers with insecure interfaces frequently serve as vectors for post-exploitation persistence and system-level control.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a low-privileged local user to execute code with elevated (system) privileges. This can result in complete system compromise, the disabling of security software, and unauthorized persistence on the affected host. The vulnerability affects systems running the Kingston FURY CTRL RGB Control Software version 2.0.65.0 on the Windows operating system. Given the public availability of the exploit, any endpoint with this software installed is at high risk of lateral movement or privilege escalation if a user account is compromised.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of endpoints running Kingston FURY CTRL RGB Control Software 2.0.65.0. If the software is not business-critical, uninstall it across the fleet to remove the vulnerable driver. For systems where the software must be maintained, implement strict local access controls to minimize the threat of local exploitation. Monitor for the loading of the NTIOLib_KSFX.sys driver on endpoints, especially if loaded by unexpected processes or in unusual paths, and audit local user account activity.\u003c/p\u003e\n","date_modified":"2026-08-10T01:50:28Z","date_published":"2026-08-10T01:50:28Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kingston-privilege-escalation/","summary":"Kingston FURY CTRL RGB Control Software version 2.0.65.0 contains a vulnerability in the NTIOLib_KSFX.sys driver that allows for local privilege escalation due to improper privilege management.","title":"Local Privilege Escalation in Kingston FURY CTRL RGB Control Software","url":"https://feed.craftedsignal.io/briefs/2026-08-kingston-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - FURY CTRL RGB Control Software (2.0.65.0)","version":"https://jsonfeed.org/version/1.1"}