Skip to content
Threat Feed

Tag

Driver-Vulnerability

6 briefs RSS
high advisory

CVE-2026-9492 - Improper Access Control in Gigabyte Control Center MBStorage Module

An Improper Access Control vulnerability (CVE-2026-9492) in the MBStorage DRAM lighting control module of Gigabyte Control Center (GCC) allows authenticated local attackers to achieve kernel-level privileges by sending specific IOCTL commands to the `MyPortIO_x64.sys` driver, enabling arbitrary physical memory read/write.

Gigabyte Control Center +1 privilege-escalation vulnerability windows driver-vulnerability local-privilege-escalation
1t 1c
high advisory

CVE-2026-15506: SecureAge CatchPulse Local Privilege Escalation via Heap-based Buffer Overflow

A heap-based buffer overflow vulnerability, CVE-2026-15506, in the `saappctl.sys` driver of SecureAge CatchPulse versions up to 10.9.3 allows a local attacker to achieve privilege escalation, and an exploit has been publicly disclosed.

CatchPulse up to 10.9.3 vulnerability privilege-escalation driver-vulnerability heap-overflow local-access
1t 1c
high advisory

CVE-2026-57851 — MSI Feature Manager Kernel Driver Local Privilege Escalation

A local privilege escalation vulnerability (CVE-2026-57851) exists in the MSI Feature Manager's KernCoreLib64.sys kernel driver that allows any local user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without requiring administrator privileges, enabling manipulation of kernel objects, tampering with kernel-mode callbacks, bypassing Protected Process Light, and disabling security software.

MSI Feature Manager privilege-escalation vulnerability windows driver-vulnerability
1t 1c
high advisory

CVE-2026-46163 wifi: b43legacy Firmware Key Index Vulnerability

CVE-2026-46163 is a vulnerability in the b43legacy WiFi driver related to a missing bounds check on the firmware key index in the RX path, potentially leading to memory corruption.

wifi memory corruption driver vulnerability CVE-2026-46163
2r 1c
high advisory

Qualcomm Driver IOCTL Memory Corruption Vulnerability

A memory corruption vulnerability, CVE-2025-47408, exists in Qualcomm drivers when another driver calls an IOCTL with an invalid input/output buffer, potentially leading to code execution or denial of service.

memory corruption ioctl driver vulnerability cve-2025-47408
2r 1t 1c
high advisory

Qualcomm Camera Driver Memory Corruption Vulnerability

A memory corruption vulnerability exists in Qualcomm camera sensor drivers due to insufficient output buffer size validation during IOCTL processing, potentially leading to arbitrary code execution.

memory-corruption driver-vulnerability qualcomm
2r 1t 1c