Description
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for Windows up to and including 6.42 Build 63 installs idmwfp.sys, a Windows kernel driver that exposes the \.\IDMWFP device interface to authenticated local users. The device object is created with an access control descriptor equivalent to D:P(A;;GA;;;AU), granting Authenticated Users generic access to the driver. The driver's IOCTL 0x12C028 handler accepts registry-operation subcommands 0x0C through 0x0F and processes caller-controlled registry paths and values. These handlers do not authenticate the caller, do not enforce the caller's registry permissions, and do not restrict operations to IDM-owned registry namespaces. A low-privileged local authenticated user can therefore read, create, modify, and delete arbitrary registry values under HKLM and HKU through the kernel driver. This includes registry configuration consumed by privileged Windows services and drivers and enables Local Privilege Escalation, high-privilege persistence, unauthorized system configuration disclosure or modification, and compromise of system confidentiality, integrity, and availability. Exploitation requires local access, low privileges, and no user interaction. A public proof of concept is available. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The flaw resides in the kernel driver idmwfp.sys included with Tonec Internet Download Manager up to version 6.42 Build 63. A local authenticated user can send a specific IOCTL request that causes the driver to perform registry operations on arbitrary HKLM and HKU keys without verifying the caller’s permissions. This bypass gives the attacker the ability to read, modify, or delete registry settings used by privileged services, allowing the attacker to elevate local privileges to SYSTEM. The weakness maps to improper privilege management (CWE‑266) and improper access control (CWE‑284).

Affected Systems

Tonec Internet Download Manager up to and including version 6.42 Build 63 on Windows machines is affected via the idmwfp.sys kernel driver; other components of the application are not impacted.

Risk and Exploitability

The CVSS score of 9.3 signals a high severity risk. While the EPSS score is less than 1%, indicating a low current exploitation probability, the publicly available proof‑of‑concept code and lack of an available vendor response mean the vulnerability can be leveraged by a local attacker with no additional user interaction. The issue is not listed in the CISA KEV catalog, but the potential for privilege escalation warrants immediate attention.

Generated by OpenCVE AI on September 21, 2026 at 00:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Internet Download Manager as soon as it becomes available.
  • If a patch is not yet released, uninstall the Internet Download Manager application to remove the vulnerable idmwfp.sys driver.
  • Alternatively disable or remove the idmwfp.sys kernel driver via Device Manager or by deleting its driver service entry to prevent it from loading.

Generated by OpenCVE AI on September 21, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for Windows up to and including 6.42 Build 63 installs idmwfp.sys, a Windows kernel driver that exposes the \.\IDMWFP device interface to authenticated local users. The device object is created with an access control descriptor equivalent to D:P(A;;GA;;;AU), granting Authenticated Users generic access to the driver. The driver's IOCTL 0x12C028 handler accepts registry-operation subcommands 0x0C through 0x0F and processes caller-controlled registry paths and values. These handlers do not authenticate the caller, do not enforce the caller's registry permissions, and do not restrict operations to IDM-owned registry namespaces. A low-privileged local authenticated user can therefore read, create, modify, and delete arbitrary registry values under HKLM and HKU through the kernel driver. This includes registry configuration consumed by privileged Windows services and drivers and enables Local Privilege Escalation, high-privilege persistence, unauthorized system configuration disclosure or modification, and compromise of system confidentiality, integrity, and availability. Exploitation requires local access, low privileges, and no user interaction. A public proof of concept is available. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References

Sun, 13 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Tonec Internet Download Manager Kernel Driver idmwfp.sys access control
First Time appeared Tonec
Tonec internet Download Manager
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:tonec:internet_download_manager:*:*:*:*:*:*:*:*
Vendors & Products Tonec
Tonec internet Download Manager
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Tonec Internet Download Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:00:54.122Z

Reserved: 2026-09-12T08:15:21.877Z

Link: CVE-2026-90493

cve-icon Vulnrichment

Updated: 2026-09-15T13:49:17.923Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T03:16:27.370

Modified: 2026-09-15T15:17:27.347

Link: CVE-2026-90493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control