CVE-2026-82628

8.8

Colorful · iGameCenter

Colorful iGameCenter version 2.0.0.81 contains an improper privilege management vulnerability in WinRing0x64.sys, allowing local attackers to escalate privileges via crafted IOCTL requests.

Executive summary

A high-severity privilege management vulnerability in Colorful iGameCenter 2.0.0.81 allows local users to achieve full system compromise.

Vulnerability

The vulnerability exists within the WinRing0x64.sys library, specifically the sub_11504 function, which handles IOCTL dispatching. By manipulating input parameters such as PhysicalAddress, AlignNumer, or AlignSize, a locally authenticated attacker can trigger improper privilege management, potentially leading to arbitrary code execution with kernel-level permissions.

Business impact

The exploitation of this flaw poses a severe risk to organizational security, as it allows a standard local user to bypass security boundaries and gain elevated system privileges. With a CVSS score of 8.8, this vulnerability is categorized as high, reflecting the potential for total system compromise, data theft, and the installation of persistent malicious software. Such an event would result in significant operational disruption and loss of confidentiality for the affected workstation.

Remediation

Immediate Action: Restrict access to the affected system to trusted users only and monitor for vendor-provided updates to the WinRing0x64.sys driver.

Proactive Monitoring: Audit system logs for unusual process execution or attempts to access kernel-mode drivers from low-privileged user accounts.

Compensating Controls: Utilize endpoint detection and response (EDR) solutions to monitor for unauthorized calls to the WinRing0x64.sys driver and enforce strict least-privilege policies for all local users.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for complete system compromise via kernel-mode exploitation, this vulnerability requires immediate attention. Administrators should prioritize the identification of all instances of Colorful iGameCenter 2.0.0.81 within their environment and limit local access to these systems until a security patch is released and applied.

Sources

Originally found and disclosed by Element2023H (VulDB User), with VulDB Vulnerability Moderation Team (coordinator), per the CVE Program record.