{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/icue-v5.9.105/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:corsair:icue:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2024-22002"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iCUE (v5.9.105)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","dll-hijacking","windows","cve-2024-22002"],"_cs_type":"advisory","_cs_vendors":["Corsair"],"content_html":"\u003cp\u003eCorsair iCUE v5.9.105 contains a high-severity local privilege escalation vulnerability, tracked as CVE-2024-22002. The vulnerability resides within the iCUEUpdateService, which spawns the 'cuepkg.exe' process with 'NT AUTHORITY\\SYSTEM' privileges to handle software updates. During this process, 'cuepkg.exe' attempts to load specific DLLs from the installation subdirectory '\\cuepkg-1.2.6'.\u003c/p\u003e\n\u003cp\u003eThe security flaw stems from insecure directory permissions that allow standard, unprivileged users to write files into this specific installation path. An attacker can place a malicious DLL (e.g., 'profapi.dll', 'MSASN1.dll', or 'NTASN1.dll') into the directory. When the 'iCUEUpdateService' triggers an update - either automatically or manually via the user interface - 'cuepkg.exe' loads the attacker-controlled library, executing arbitrary code with system-level privileges. This vulnerability enables a local user to compromise the integrity and confidentiality of the host operating system.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unprivileged user identifies the writeable directory path: '%INSTALLDIR%\\cuepkg-1.2.6'.\u003c/li\u003e\n\u003cli\u003eThe attacker compiles a malicious DLL designed to perform unauthorized administrative actions (e.g., adding a user to the local Administrators group).\u003c/li\u003e\n\u003cli\u003eThe attacker copies the malicious DLL into the target directory, masquerading as 'profapi.dll', 'MSASN1.dll', or 'NTASN1.dll'.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers the iCUE update mechanism by launching the Corsair iCUE application or manually selecting \u0026quot;Check for updates\u0026quot;.\u003c/li\u003e\n\u003cli\u003eThe 'iCUEUpdateService' initiates 'cuepkg.exe' to process the update.\u003c/li\u003e\n\u003cli\u003e'cuepkg.exe' loads the malicious DLL from the local directory instead of the legitimate system folder.\u003c/li\u003e\n\u003cli\u003eThe operating system executes the malicious code within the context of the 'cuepkg.exe' process running as 'NT AUTHORITY\\SYSTEM'.\u003c/li\u003e\n\u003cli\u003eThe attacker gains full system control, such as privilege escalation to local Administrator.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-22002 allows a local, low-privileged user to gain full SYSTEM privileges on the affected Windows workstation. This impacts the security posture of the host, enabling total system compromise, exfiltration of sensitive data, and persistence. Given the high popularity of Corsair iCUE among gaming and enthusiast users, many systems are potentially at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit systems running Corsair iCUE v5.9.105 for insecure file permissions in the installation directory.\u003c/li\u003e\n\u003cli\u003eMonitor process creation logs for 'cuepkg.exe' activity, specifically inspecting the working directory for unexpected DLL loading.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect suspicious file creation events in the iCUE installation path.\u003c/li\u003e\n\u003cli\u003eUpgrade Corsair iCUE software to the latest version immediately once a patch is provided by the vendor.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T17:46:48Z","date_published":"2026-08-29T17:46:48Z","id":"https://feed.craftedsignal.io/briefs/2026-08-corsair-icue-lpe/","summary":"Corsair iCUE v5.9.105 contains a DLL hijacking vulnerability (CVE-2024-22002) in the iCUEUpdateService, allowing local unprivileged users to achieve SYSTEM-level code execution.","title":"Local Privilege Escalation in Corsair iCUE via DLL Hijacking","url":"https://feed.craftedsignal.io/briefs/2026-08-corsair-icue-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - ICUE (V5.9.105)","version":"https://jsonfeed.org/version/1.1"}