{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/igamecenter-2.0.0.81/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:colorful:igamecenter:2.0.0.81:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-82628"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iGameCenter (2.0.0.81)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","local-privilege-escalation","windows"],"_cs_type":"advisory","_cs_vendors":["Colorful"],"content_html":"\u003cp\u003eA high-severity vulnerability (CVE-2026-82628) exists within the Colorful iGameCenter version 2.0.0.81 software suite. The flaw resides in the WinRing0x64.sys kernel-mode driver, specifically within the sub_11504 function responsible for handling IOCTL requests. An attacker with local access to the affected system can provide maliciously crafted arguments - specifically targeting the PhysicalAddress, AlignNumer, or AlignSize parameters - to trigger improper privilege management. Successful exploitation allows a local user to escalate privileges to the level of the kernel, potentially leading to full system compromise. As this vulnerability requires local access and interaction with the device driver interface, it primarily poses a threat to systems where low-privileged users can execute arbitrary code or interact with vulnerable hardware drivers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in local privilege escalation, allowing an attacker to execute arbitrary code with kernel-level permissions. This can lead to total system compromise, bypass of security controls, and persistent access that is difficult to detect or remove.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all systems running Colorful iGameCenter 2.0.0.81 in the environment using endpoint inventory tools.\u003c/li\u003e\n\u003cli\u003eRestrict access to the WinRing0x64.sys driver interface if possible or remove/update the vulnerable version of the iGameCenter software suite.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual process creation or driver loading activity that may indicate an attempt to interact with third-party hardware drivers for privilege escalation.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-31T09:16:20Z","date_published":"2026-08-31T09:16:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82628/","summary":"Colorful iGameCenter 2.0.0.81 is vulnerable to local privilege escalation due to improper input validation within the WinRing0x64.sys IOCTL dispatch handler.","title":"Local Privilege Escalation in Colorful iGameCenter WinRing0x64.sys","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82628/"}],"language":"en","title":"CraftedSignal Threat Feed - IGameCenter (2.0.0.81)","version":"https://jsonfeed.org/version/1.1"}