Impact
The flaw resides in the kernel driver idmwfp.sys included with Tonec Internet Download Manager up to version 6.42 Build 63. A local authenticated user can send a specific IOCTL request that causes the driver to perform registry operations on arbitrary HKLM and HKU keys without verifying the caller’s permissions. This bypass gives the attacker the ability to read, modify, or delete registry settings used by privileged services, allowing the attacker to elevate local privileges to SYSTEM. The weakness maps to improper privilege management (CWE‑266) and improper access control (CWE‑284).
Affected Systems
Tonec Internet Download Manager up to and including version 6.42 Build 63 on Windows machines is affected via the idmwfp.sys kernel driver; other components of the application are not impacted.
Risk and Exploitability
The CVSS score of 9.3 signals a high severity risk. While the EPSS score is less than 1%, indicating a low current exploitation probability, the publicly available proof‑of‑concept code and lack of an available vendor response mean the vulnerability can be leveraged by a local attacker with no additional user interaction. The issue is not listed in the CISA KEV catalog, but the potential for privilege escalation warrants immediate attention.
OpenCVE Enrichment