Impact
A vulnerability in Almico Speedfan version 4.52 exists in the KiSystemCall64 function of the speedfan.sys driver, which handles MSR index data. When a local attacker manipulates the driver, it causes a memory leak, leading to gradual exhaustion of system memory and eventual degradation or crash of the host. This flaw falls under CWE‑401 and CWE‑404, reflecting unsigned memory management and failure to release resources. The exploit is local only and the vendor has not issued a response or patch.
Affected Systems
Almico Speedfan 4.52 running on Windows platforms that load the speedfan.sys kernel driver. No other versions or editions are listed as impacted.
Risk and Exploitability
The CVSS base score is 4.6, indicating a moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited public exploitation data. Attackers must gain local access to the target machine and then trigger the driver through crafted input to create a memory leak. Once the memory reservoir is depleted, the system may become unstable or unresponsive, compromising availability for legitimate users.
OpenCVE Enrichment