Description
A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Implement Mitigation
AI Analysis

Impact

The vulnerability resides in the sub_11008 function of the ComputerZ_x64.sys driver used by Chengdu Qilu Technology Ludashi. Manipulating the PhysicalAddress argument while calling this function allows an attacker to read sensitive data from memory, resulting in information disclosure. The flaw can expose confidential data, compromising confidentiality without enabling direct code execution.

Affected Systems

This issue affects Chengdu Qilu Technology Ludashi version 6.1026.4715.714. The vulnerability exists in the ComputerZ_x64.sys driver component included in this release.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate risk. The flaw requires local execution and the vendor has not released a fix, leaving the vulnerability unpatched. An exploit has been published and may be used by attackers. The vulnerability is not listed in the CISA KEV catalog, and the EPSS score of < 1% indicates a very low exploitation probability, meaning the attacker must rely on local privileged access. The primary risk is that privileged local users could read sensitive system memory.

Generated by OpenCVE AI on September 15, 2026 at 17:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict local administrative privileges and enforce least‑privilege policies to limit the ability of local users to interact with system drivers.
  • Implement driver signing enforcement and load policies that allow only trusted drivers, reducing the chance that a malicious manipulation of the ComputerZ_x64.sys driver can occur.
  • Enable detailed audit logging for driver operations and monitor for abnormal usage of the PhysicalAddress parameter, alerting on suspicious activity to detect potential exploitation.

Generated by OpenCVE AI on September 15, 2026 at 17:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Chengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosure
First Time appeared Chengdu Qilu Technology
Chengdu Qilu Technology ludashi
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:chengdu_qilu_technology:ludashi:*:*:*:*:*:*:*:*
Vendors & Products Chengdu Qilu Technology
Chengdu Qilu Technology ludashi
References
Metrics cvssV2_0

{'score': 1.4, 'vector': 'AV:L/AC:L/Au:M/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Chengdu Qilu Technology Ludashi
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:00:38.987Z

Reserved: 2026-09-12T08:46:37.771Z

Link: CVE-2026-90503

cve-icon Vulnrichment

Updated: 2026-09-15T13:36:08.541Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T09:16:31.933

Modified: 2026-09-15T15:17:27.650

Link: CVE-2026-90503

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control