Tag
Improper Access Control in Tonec Internet Download Manager Kernel Driver
1 TTP 1 CVECVE-2026-90493 is a local privilege escalation vulnerability in the Tonec Internet Download Manager idmwfp.sys kernel driver, allowing attackers with local access to manipulate improper access controls.
Local Privilege Escalation in PassMark Software Drivers
1 TTP 1 CVEPassMark PerformanceTest, BurnInTest, and OSForensics contain a vulnerability in the DirectIo64.sys driver that allows local users to clear arbitrary physical memory bits, enabling privilege escalation.
Exposure of Certificate Authority Private Keys in IBM AIX and PowerVM VIOS
3 TTPs 1 CVEIBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 contain intermediate CA private keys within publicly available update files, potentially allowing remote attackers to bypass security restrictions.
Integer Overflow in AMD KFD Driver
1 CVEA 32-bit integer overflow vulnerability in the AMD KFD kernel driver allows for potential memory corruption during CWSR size calculations.
NULL Pointer Dereference in Linux ath11k Wi-Fi Driver
1 TTP 1 CVECVE-2026-68362 describes a NULL pointer dereference vulnerability in the Linux kernel ath11k driver that may lead to denial-of-service or potential code execution via crafted interactions.
Vulnerability in AMD Display Driver for Linux Kernel
1 TTP 1 CVEA memory management flaw in the AMD display driver (drm/amd/display) for the Linux kernel allows for improper handling of DisplayPort Multi-Stream Transport (DP MST) configurations.
Vulnerability in Linux KVM MMU Page Management
1 TTP 1 CVECVE-2026-64561 identifies a flaw in the Linux KVM hypervisor where incorrect validation of MMU pages could lead to memory management inconsistencies.
Linux Kernel MPLS NULL Pointer Dereference Vulnerability
2 TTPs 1 CVEA NULL pointer dereference vulnerability in the Linux kernel's MPLS subsystem, specifically affecting configurations where CONFIG_INET is disabled, can lead to a denial-of-service condition.
Kernel Local Privilege Escalation Vulnerability CVE-2026-17523
1 TTP 1 CVEA critical local privilege escalation (LPE) vulnerability, tracked as CVE-2026-17523 and identified as an Expired Pointer Dereference (CWE-825), exists within the kernel, primarily affecting Red Hat Enterprise Linux 8, enabling an unprivileged local user to execute arbitrary code within the kernel, leading to root privileges and full control over the compromised system.
Linux Kernel proc_readdir_de() Use-After-Free Local Privilege Escalation
2 rules 1 TTP 1 CVE 3 IOCsA local privilege escalation vulnerability exists in the Linux Kernel versions ~3.14+ through 6.18-rc5 due to a use-after-free in the proc_readdir_de() function, where a concurrent traversal can dereference a freed entry's fields during network device unregistration, leading to privilege escalation via modprobe_path overwrite.