CVE-2026-94403

8.8

ColorFul · iGameCenter

ColorFul iGameCenter version 1.0.3.4 contains an untrusted pointer dereference vulnerability in the ene.sys library IOCTL handler, potentially allowing local code execution.

Executive summary

A high-severity untrusted pointer dereference vulnerability in ColorFul iGameCenter version 1.0.3.4 poses a significant risk of local system compromise.

Vulnerability

This vulnerability involves an untrusted pointer dereference within the function sub_140001AF0 of the ene.sys library. The flaw is triggered via the IOCTL handler and requires an attacker to have local access to the system.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for total system compromise, including high impacts on confidentiality, integrity, and availability. Successful exploitation allows a local user to execute arbitrary code with elevated privileges, potentially leading to full system takeover and persistent unauthorized access to sensitive data.

Remediation

Immediate Action: Since there is no official patch available from the vendor, users should restrict access to the affected system to authorized personnel only. If the software is not mission-critical, consider uninstalling or disabling the iGameCenter utility until a security update is released.

Proactive Monitoring: Monitor system logs for unauthorized attempts to interact with the ene.sys driver or unusual IOCTL request patterns. Review process execution logs for unexpected child processes spawned by the iGameCenter service.

Compensating Controls: Implement strict local privilege management to prevent unauthorized users from executing code on the host. Ensure endpoint protection solutions are configured to detect and block malicious driver-level activities.

Exploitation status

Public Exploit Available: Yes, a public exploit has been made available to the public as noted in the vulnerability documentation.

Analyst recommendation

Given the lack of vendor response and the existence of a public exploit, this vulnerability presents a significant risk to affected environments. Organizations should prioritize isolating systems running ColorFul iGameCenter 1.0.3.4 and monitor for security updates. If an update remains unavailable, removal of the software is the most effective way to eliminate this attack surface.

More ColorFul CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Bigcat (VulDB User), with VulDB CNA Team (coordinator), per the CVE Program record.