Impact
The vulnerability is a untrusted pointer dereference inside the sub_140001AF0 function of the IOCTL handler in the ene.sys library. This flaw allows a local attacker to manipulate memory pointers, potentially leading to arbitrary code execution or escalation of privileges on the affected system.
Affected Systems
ColorFul iGameCenter version 1.0.3.4 is the only known affected product.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score is not available, but a public exploit has been released, meaning the risk is significant for any system running the vulnerable version. The attack can only be executed locally, so the primary threat is for users who can access the machine but not for remote attackers. The vulnerability is not listed in CISA’s KEV catalog, but the presence of a public exploit and a high CVSS score warrants immediate attention.
OpenCVE Enrichment