Description
FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Windows 11 25H2 HLK (Hardware Lab Kit). The fixed driver may be available through Windows Update or from Lenovo directly.
Published: 2026-07-07
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in FluxInk Color Management Driver (TcnPeripheral64.sys 1.0.7.2), allowing a standard user to map arbitrary physical memory through the kernel object \\Device\\PhysicalMemory. This misconfiguration enables reading and writing kernel memory, providing a local privilege escalation vector that corresponds to CWE‑269. If an attacker successfully exploits this flaw, they can gain elevated privileges and compromise system integrity.

Affected Systems

FluxInk Color Management Driver (TcnPeripheral64.sys) version 1.0.7.2 is a vendor‑provided driver that is fixed in 1.0.7.6. The fixed driver is available in the Windows 11 25H2 HLK (Hardware Lab Kit) and may be delivered through Windows Update or Lenovo’s support channels.

Risk and Exploitability

The CVSS score of 8.4 indicates significant severity. The EPSS score of < 1% demonstrates a very low probability that this vulnerability will be actively exploited, and it is not listed in Based on the description, the attack vector is local user access, making it a common scenario on systems with the affected driver. While the exploit requires only local user privileges, the overall risk of real‑world exploitation remains low due to the low exploitation probability indicated by EPSS.

Generated by OpenCVE AI on July 26, 2026 at 19:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patched driver version 1.0.7.6 or later.
  • Install the latest Windows Update for Windows 11 25H2 HLK to obtain the corrected driver.
  • If the update is not yet available, remove or uninstall the FluxInk Color Management Driver until a patch is released.

Generated by OpenCVE AI on July 26, 2026 at 19:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Fluxink
Fluxink color Management Driver
Vendors & Products Fluxink
Fluxink color Management Driver

Tue, 07 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Windows 11 25H2 HLK (Hardware Lab Kit). The fixed driver may be available through Windows Update or from Lenovo directly.
Title FluxInk Color Management Driver local privilege escalation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Fluxink Color Management Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-07-21T17:04:11.426Z

Reserved: 2026-07-01T15:47:30.055Z

Link: CVE-2026-58583

cve-icon Vulnrichment

Updated: 2026-07-21T17:04:04.915Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management