Impact
The flaw in Power Sofware PowerISO 9.3.0.0 allows local users to manipulate the scdemu.sys kernel driver and trigger improper privilege management. The result is a high‑severity local privilege escalation that can grant an attacker SYSTEM level rights. The vulnerability is based on CWE-266 and CWE-269, indicating incorrect privilege handling and insufficient permission checks. The attack is only possible with local access, but once executed an attacker could run arbitrary code with elevated privileges, compromise the system, and bypass standard security controls.
Affected Systems
The vulnerability is present only in Power Sofware PowerISO version 9.3.0.0. The affected component is the scdemu.sys kernel driver located in C:\Windows\System32\drivers. No other versions or products have been reported to be affected at this time.
Risk and Exploitability
The CVSS score of 8.5 points to a high severity risk. Although the EPSS score is not available, the vulnerability has an active public exploit that could be used by attackers with local console or remote desktop access on the same machine. The vulnerability is not listed in CISA's KEV catalog, but the existence of a publicly available exploit and the lack of a vendor response elevate the risk, making immediate remediation critical. Exploitation requires local access and entails manipulating kernel privileges, a difficult but well‑known attack path that can lead to full system compromise.
OpenCVE Enrichment