CVE-2026-19381

7.8

Kingston · FURY CTRL RGB Control Software

Kingston FURY CTRL RGB Control Software version 2.0.65.0 contains an improper privilege management vulnerability that could allow local attackers to escalate privileges.

Executive summary

A high-severity privilege escalation vulnerability exists in Kingston FURY CTRL RGB Control Software, potentially allowing a local attacker to gain unauthorized control over the system.

Vulnerability

This vulnerability involves improper privilege management and incorrect privilege assignment (CWE-269, CWE-266). The flaw requires a local attacker with low privileges to interact with the software to achieve full system compromise.

Business impact

Successful exploitation of this vulnerability allows a local user to execute commands with elevated permissions, leading to full system compromise. With a CVSS score of 7.8, this represents a significant risk to the integrity and availability of workstations running this software, especially in environments where non-administrative users have local access to machines.

Remediation

Immediate Action: Currently, there is no official patch released by the vendor. Users should restrict local access to systems running this software and consider disabling the service if it is not mission-critical.

Proactive Monitoring: Monitor system logs for unexpected privilege escalation events, such as unauthorized creation of administrative accounts or suspicious processes running under the SYSTEM context.

Compensating Controls: Implement strict application allowlisting to prevent unauthorized code execution and ensure that local users operate with the principle of least privilege.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for complete system takeover, organizations should treat this vulnerability with high priority. We recommend isolating affected systems until a security update is provided by Kingston and monitoring for any anomalous local activity that suggests privilege escalation attempts.

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section