Description
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used.
Published: 2026-08-07
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in DeepCool DisplayService 1.2.12 permits an attacker who can manipulate the executable file DeepCoolDisplayService.exe to bypass normal access controls. The vulnerability is classified as improper access control (CWE‑266 and CWE‑284) and allows local users to gain privileges equivalent to the system account by exploiting the exposed control channel. When executed, the attacker can alter the service’s behavior and potentially execute arbitrary code with elevated rights.

Affected Systems

DeepCool DisplayService version 1.2.12 on systems running the DeepCool software suite. The issue is tied to the file located at C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe and affects installations using this binary.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.5, highlighting its high severity. The attack requires local access and is not remotely exploitable, but the exploit is publicly available, meaning a local attacker can readily use it. While EPSS data is not available and the issue is not listed in CISA’s KEV catalog, the combination of high local impact and public exploit code makes it a significant risk for any organization that runs the affected service locally.

Generated by OpenCVE AI on August 7, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DeepCool DisplayService to a patched version that resolves the access control flaw.
  • If an immediate patch is unavailable, disable or remove the DeepCoolDisplayService.exe binary to prevent local manipulation.
  • Restrict local file permissions and remove unauthenticated access to the named pipe control channel used by the service.
  • Monitor event logs for attempts to access or modify DeepCoolDisplayService.exe and investigate any suspicious activity.

Generated by OpenCVE AI on August 7, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used.
Title DeepCool DisplayService DeepCoolDisplayService.exe access control
First Time appeared Deepcool
Deepcool displayservice
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:deepcool:displayservice:*:*:*:*:*:*:*:*
Vendors & Products Deepcool
Deepcool displayservice
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Deepcool Displayservice
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-07T03:45:08.513Z

Reserved: 2026-08-06T20:03:39.373Z

Link: CVE-2026-19192

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T05:30:07Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control