Description
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-07
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Power Sofware PowerISO 9.3.0.0 allows local users to manipulate the scdemu.sys kernel driver and trigger improper privilege management. The result is a high‑severity local privilege escalation that can grant an attacker SYSTEM level rights. The vulnerability is based on CWE-266 and CWE-269, indicating incorrect privilege handling and insufficient permission checks. The attack is only possible with local access, but once executed an attacker could run arbitrary code with elevated privileges, compromise the system, and bypass standard security controls.

Affected Systems

The vulnerability is present only in Power Sofware PowerISO version 9.3.0.0. The affected component is the scdemu.sys kernel driver located in C:\Windows\System32\drivers. No other versions or products have been reported to be affected at this time.

Risk and Exploitability

The CVSS score of 8.5 points to a high severity risk. Although the EPSS score is not available, the vulnerability has an active public exploit that could be used by attackers with local console or remote desktop access on the same machine. The vulnerability is not listed in CISA's KEV catalog, but the existence of a publicly available exploit and the lack of a vendor response elevate the risk, making immediate remediation critical. Exploitation requires local access and entails manipulating kernel privileges, a difficult but well‑known attack path that can lead to full system compromise.

Generated by OpenCVE AI on August 7, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor's patch or upgrade PowerISO to a version that fixes the scdemu.sys privilege management flaw.
  • If a patch is not yet available, disable or uninstall the scdemu.sys kernel driver until a fix is released, provided the functionality is not required.
  • Restrict local access to administrators only and enable Windows User Account Control to reduce the attack surface.

Generated by OpenCVE AI on August 7, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title Power Sofware PowerISO Kernel Driver scdemu.sys privileges management
First Time appeared Poweriso
Poweriso poweriso
Weaknesses CWE-266
CWE-269
CPEs cpe:2.3:a:poweriso:poweriso:*:*:*:*:*:*:*:*
Vendors & Products Poweriso
Poweriso poweriso
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Poweriso Poweriso
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-07T15:32:50.309Z

Reserved: 2026-08-06T19:56:04.969Z

Link: CVE-2026-19189

cve-icon Vulnrichment

Updated: 2026-08-07T15:32:42.661Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T03:16:18.450

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-19189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T03:30:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-269

    Improper Privilege Management