CVE-2026-82628
largeLocal Privilege Escalation via WinRing0x64.sys Driver in Colorful iGameCenter
Colorful iGameCenter 2.0.0.81 ships a kernel driver, WinRing0x64.sys, whose IOCTL Dispatch handler (function sub_11504) fails to properly validate caller-supplied arguments — PhysicalAddress, AlignNumer and AlignSize — resulting in improper privilege management (CWE-266/CWE-269). A local, low-privileged attacker who can execute code on the machine and send crafted IOCTLs to the driver can manipulate these values to gain elevated access, most plausibly by mapping or writing arbitrary physical memory and escalating to SYSTEM/kernel privileges. Successful exploitation yields full control of the affected system, consistent with the critical CVSS 4.0 score of 9.3 and high impact on confidentiality, integrity and availability. Affected users are Windows owners of Colorful graphics cards running the iGameCenter tuning/monitoring utility (version 2.0.0.81 confirmed; other version ranges are not specified in the disclosure). No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known, and EPSS estimates only a ~0.1% probability of exploitation within 30 days.
What to do: Upgrade iGameCenter as soon as Colorful publishes a fixed build — no patched version is identified in the disclosure, so check the vendor's download/support pages for anything newer than 2.0.0.81. As an interim mitigation, uninstall or stop the utility and confirm the bundled WinRing0x64.sys driver is not loaded, prioritizing shared or multi-user Windows machines where any low-privileged local user could exploit the driver. Note that many other utilities ship their own copies of WinRing0x64.sys, which should be tracked and assessed separately.
| Colorful iGameCenter (vulnerable component: bundled WinRing0x64.sys kernel driver, IOCTL Dispatch) | 2.0.0.81 confirmed affected; no other version ranges specified in the available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement.
- Weakness
- CWE-266, CWE-269
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.