{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/power-sofware/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-19189"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PowerISO (9.3.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Power Sofware"],"content_html":"\u003cp\u003eA security vulnerability has been identified in PowerISO version 9.3.0.0, specifically within the kernel driver component 'scdemu.sys' located in 'C:\\Windows\\System32\\drivers'. The flaw stems from improper privilege management, which allows an attacker with existing local access to the system to escalate their privileges to a higher integrity level. This vulnerability is significant because it involves kernel-mode driver code, which historically offers a path for non-privileged users to execute arbitrary code with kernel permissions. Public exploit material is currently available for this vulnerability, increasing the risk of exploitation in targeted attacks. The vendor has not responded to disclosure attempts. Defenders should prioritize auditing the usage of this driver and identifying systems where PowerISO 9.3.0.0 is installed, as there is currently no vendor-provided patch.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows a local attacker to bypass standard operating system security controls to gain elevated privileges. This can result in full system compromise, the ability to disable security software, and persistence at the kernel level. As PowerISO is a common utility, organizations running this software are potentially at risk if an attacker gains initial low-privilege access to an endpoint.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all endpoints within the environment running PowerISO version 9.3.0.0 using software inventory management tools.\u003c/li\u003e\n\u003cli\u003eImplement strict application control policies to restrict unauthorized users from executing code or running utilities in directories where PowerISO resides.\u003c/li\u003e\n\u003cli\u003eMonitor for the loading of the 'scdemu.sys' driver in environments where PowerISO is not explicitly required for business operations.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of the PowerISO software; if not critical, remove the application to eliminate the attack surface provided by the vulnerable driver.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T03:29:46Z","date_published":"2026-08-07T03:29:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-poweriso-privilege-escalation/","summary":"PowerISO version 9.3.0.0 contains a vulnerability in the scdemu.sys kernel driver that enables local attackers to perform privilege escalation through improper privilege management.","title":"Local Privilege Escalation in PowerISO Kernel Driver","url":"https://feed.craftedsignal.io/briefs/2026-08-poweriso-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Power Sofware","version":"https://jsonfeed.org/version/1.1"}