{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/igamecenter-1.0.3.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:colorful:igamecenter:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94403"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iGameCenter (1.0.3.4)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["Colorful"],"content_html":"\u003cp\u003eA security vulnerability has been identified in ColorFul iGameCenter version 1.0.3.4, specifically affecting the IOCTL handler function sub_140001AF0 located within the ene.sys driver. This vulnerability allows an unprivileged local attacker to trigger an untrusted pointer dereference. Because the flaw resides within a kernel-mode driver, successful exploitation could lead to local privilege escalation or complete system instability. Publicly available exploit code currently exists, and the vendor has not provided a patch or response to the disclosure. Defenders should be aware that this requires local access, making it a critical concern for multi-user systems or environments where local user execution is common.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains low-privileged access to the target Windows system.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the loaded ene.sys driver on the system.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious IOCTL request directed at the driver device object.\u003c/li\u003e\n\u003cli\u003eThe malicious request reaches the vulnerable sub_140001AF0 function within ene.sys.\u003c/li\u003e\n\u003cli\u003eThe function performs an unsafe dereference of an untrusted pointer provided in the IOCTL buffer.\u003c/li\u003e\n\u003cli\u003eMemory corruption occurs, allowing for arbitrary code execution in the kernel context.\u003c/li\u003e\n\u003cli\u003eAttacker achieves local privilege escalation to SYSTEM.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to systems running ColorFul iGameCenter, as it allows local unprivileged users to gain kernel-level access. Successful exploitation can result in complete compromise of the host OS, persistence, and bypass of standard user-mode security controls.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring for the existence of the vulnerable driver file on all managed workstations. If the application is not required for business operations, uninstall it immediately to remove the attack surface. Since the vendor has not addressed the issue, consider blocking the loading of the ene.sys driver via WDAC or equivalent kernel-mode code signing policies if the driver is not business-critical.\u003c/p\u003e\n","date_modified":"2026-09-21T20:29:51Z","date_published":"2026-09-21T20:29:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-colorful-igamecenter-vuln/","summary":"ColorFul iGameCenter version 1.0.3.4 contains an untrusted pointer dereference vulnerability in the ene.sys driver that can be leveraged by local attackers for privilege escalation.","title":"Untrusted Pointer Dereference in ColorFul iGameCenter","url":"https://feed.craftedsignal.io/briefs/2026-09-colorful-igamecenter-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - IGameCenter (1.0.3.4)","version":"https://jsonfeed.org/version/1.1"}