Impact
A flaw in DeepCool DisplayService 1.2.12 permits an attacker who can manipulate the executable file DeepCoolDisplayService.exe to bypass normal access controls. The vulnerability is classified as improper access control (CWE‑266 and CWE‑284) and allows local users to gain privileges equivalent to the system account by exploiting the exposed control channel. When executed, the attacker can alter the service’s behavior and potentially execute arbitrary code with elevated rights.
Affected Systems
DeepCool DisplayService version 1.2.12 on systems running the DeepCool software suite. The issue is tied to the file located at C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe and affects installations using this binary.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, highlighting its high severity. The attack requires local access and is not remotely exploitable, but the exploit is publicly available, meaning a local attacker can readily use it. While EPSS data is not available and the issue is not listed in CISA’s KEV catalog, the combination of high local impact and public exploit code makes it a significant risk for any organization that runs the affected service locally.
OpenCVE Enrichment