Impact
The vulnerability resides in FluxInk Color Management Driver (TcnPeripheral64.sys 1.0.7.2), allowing a standard user to map arbitrary physical memory through the kernel object \\Device\\PhysicalMemory. This misconfiguration enables reading and writing kernel memory, providing a local privilege escalation vector that corresponds to CWE‑269. If an attacker successfully exploits this flaw, they can gain elevated privileges and compromise system integrity.
Affected Systems
FluxInk Color Management Driver (TcnPeripheral64.sys) version 1.0.7.2 is a vendor‑provided driver that is fixed in 1.0.7.6. The fixed driver is available in the Windows 11 25H2 HLK (Hardware Lab Kit) and may be delivered through Windows Update or Lenovo’s support channels.
Risk and Exploitability
The CVSS score of 8.4 indicates significant severity. The EPSS score of < 1% demonstrates a very low probability that this vulnerability will be actively exploited, and it is not listed in Based on the description, the attack vector is local user access, making it a common scenario on systems with the affected driver. While the exploit requires only local user privileges, the overall risk of real‑world exploitation remains low due to the low exploitation probability indicated by EPSS.
OpenCVE Enrichment