{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/tonec/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tonec:internet_download_manager:*:*:*:*:*:windows:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-90493"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Internet Download Manager (\u003c= 6.42 Build 63)"],"_cs_severities":["high"],"_cs_tags":["windows","privilege-escalation","kernel-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Tonec"],"content_html":"\u003cp\u003eCVE-2026-90493 affects Tonec Internet Download Manager versions 6.42 Build 63 and earlier on Windows. The vulnerability exists within the idmwfp.sys kernel driver, which handles filter operations for the application. A local attacker can interact with this driver to perform unauthorized operations due to improper access control mechanisms. Because the driver operates at the kernel level, this vulnerability is a significant risk for privilege escalation and security boundary bypass. Exploitation requires the attacker to already have local access to the target system. Public exploit material is available, increasing the risk of abuse. The vendor has not provided a response or a patch to address the issue at the time of disclosure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-90493 allows a local user to escalate privileges or perform unauthorized actions at the kernel level. This compromises the integrity of the host operating system, potentially enabling an attacker to disable security software, bypass endpoint protections, or maintain persistence with system-level access. Organizations utilizing affected versions of Internet Download Manager on Windows systems are at elevated risk if local users or low-privileged processes are compromised.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize restricting local access to the affected Windows systems to mitigate the threat of local privilege escalation. Given that the vendor has not provided a security update, detection and monitoring should focus on identifying unauthorized attempts to interact with the idmwfp.sys driver.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor system logs for unexpected loading of the idmwfp.sys driver or unusual IOCTL (Input/Output Control) calls directed at this driver if telemetry is available.\u003c/li\u003e\n\u003cli\u003eAudit systems running Internet Download Manager to identify instances of the vulnerable version 6.42 Build 63 or earlier.\u003c/li\u003e\n\u003cli\u003eIf the software is not mission-critical, consider uninstalling or disabling Internet Download Manager until a vendor-supplied patch is available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T03:24:00Z","date_published":"2026-09-13T03:24:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-idm-kernel-vuln/","summary":"CVE-2026-90493 is a local privilege escalation vulnerability in the Tonec Internet Download Manager idmwfp.sys kernel driver, allowing attackers with local access to manipulate improper access controls.","title":"Improper Access Control in Tonec Internet Download Manager Kernel Driver","url":"https://feed.craftedsignal.io/briefs/2026-09-idm-kernel-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Tonec","version":"https://jsonfeed.org/version/1.1"}