ZeroHour

CVE-2026-82807

niche

Local Privilege Escalation in ieungSoft Ultra RAMDisk Pro Kernel Driver

CVSS 4.0
8.5 high
EPSS
<1%p1
Published
()
Modified
AI analysis

Ultra RAMDisk Pro 1.82 ships a Windows kernel driver, URDSCSI.sys, that suffers from improper privilege management (CWE-266/CWE-269). A local attacker with only low privileges can trigger the flaw to gain elevated privileges on the host, with high impact to the system's confidentiality, integrity and availability. Any Windows machine running the affected Ultra RAMDisk Pro driver is exposed once an untrusted local user can execute code, since no user interaction is required. The advisory states the exploit has been publicly disclosed and may be used, although no standalone proof-of-concept has been catalogued; the issue is not in CISA KEV and EPSS estimates about a 0.1% chance of exploitation within 30 days. The vendor was contacted before disclosure but did not respond, and no patched version has been announced.

What to do: No fixed version has been announced, so check local Windows hosts for the presence of the Ultra RAMDisk Pro URDSCSI.sys driver and consider removing or disabling the product until the vendor issues an update. Restrict untrusted local users on systems where the driver is loaded, and monitor ieungSoft for a patch or vendor response.

Affected
ieungSoft Ultra RAMDisk Pro (URDSCSI.sys kernel driver)1.82 (version named in the disclosure; whether other versions are affected is not stated)
Estimated exposure
nichelikely at most a few thousand Windows installations; no public install counts available — No public installation metrics exist for this small-vendor commercial RAM-disk utility, so the estimate reflects its niche adoption relative to mainstream RAM-disk alternatives.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Weakness
CWE-266, CWE-269
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.