Impact
A flaw in a system driver used by Kingston FURY CTRL RGB Control Software allows local manipulation of the NTIOLib_KSFX.sys driver, resulting in misuse of privileged actions. This improper privilege management permits a local attacker to execute code with elevated rights, potentially compromising the system’s confidentiality, integrity, or availability. The vulnerability is classified as a local privilege escalation and has been publicly released with an exploit that can be used to elevate privileges on a compromised host.
Affected Systems
The vulnerability affects Kingston FURY CTRL RGB Control Software version 2.0.65.0. Users running this version on Windows systems are susceptible because the driver component is installed and potentially executed during normal operation. All systems utilizing this driver are at risk until a remedial update is applied or the driver is disabled.
Risk and Exploitability
With a CVSS score of 8.5, the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but a public exploit is known. Because the attack requires local access, the risk is confined to environments where an attacker has physical or administrative console access. Nonetheless, the availability of a public exploit and the high CVSS rating suggest that any compromised host could become a pivot point for further exploitation.
OpenCVE Enrichment