CVE-2026-19381
7.8Kingston · FURY CTRL RGB Control Software
Kingston FURY CTRL RGB Control Software version 2.0.65.0 contains an improper privilege management vulnerability that could allow local attackers to escalate privileges.
Executive summary
A high-severity privilege escalation vulnerability exists in Kingston FURY CTRL RGB Control Software, potentially allowing a local attacker to gain unauthorized control over the system.
Vulnerability
This vulnerability involves improper privilege management and incorrect privilege assignment (CWE-269, CWE-266). The flaw requires a local attacker with low privileges to interact with the software to achieve full system compromise.
Business impact
Successful exploitation of this vulnerability allows a local user to execute commands with elevated permissions, leading to full system compromise. With a CVSS score of 7.8, this represents a significant risk to the integrity and availability of workstations running this software, especially in environments where non-administrative users have local access to machines.
Remediation
Immediate Action: Currently, there is no official patch released by the vendor. Users should restrict local access to systems running this software and consider disabling the service if it is not mission-critical.
Proactive Monitoring: Monitor system logs for unexpected privilege escalation events, such as unauthorized creation of administrative accounts or suspicious processes running under the SYSTEM context.
Compensating Controls: Implement strict application allowlisting to prevent unauthorized code execution and ensure that local users operate with the principle of least privilege.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for complete system takeover, organizations should treat this vulnerability with high priority. We recommend isolating affected systems until a security update is provided by Kingston and monitoring for any anomalous local activity that suggests privilege escalation attempts.