Description
A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-21
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a untrusted pointer dereference inside the sub_140001AF0 function of the IOCTL handler in the ene.sys library. This flaw allows a local attacker to manipulate memory pointers, potentially leading to arbitrary code execution or escalation of privileges on the affected system.

Affected Systems

ColorFul iGameCenter version 1.0.3.4 is the only known affected product.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. The EPSS score is not available, but a public exploit has been released, meaning the risk is significant for any system running the vulnerable version. The attack can only be executed locally, so the primary threat is for users who can access the machine but not for remote attackers. The vulnerability is not listed in CISA’s KEV catalog, but the presence of a public exploit and a high CVSS score warrants immediate attention.

Generated by OpenCVE AI on September 21, 2026 at 19:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched or newer release of ColorFul iGameCenter if one is available from the vendor.
  • If upgrading is not possible, restrict local access to the IOCTL interface or disable the ene.sys component to block the vulnerable function.
  • Monitor system logs for signs of local exploitation attempts and anomalous privilege changes.
  • Contact the vendor for an official fix and apply it as soon as it is released.

Generated by OpenCVE AI on September 21, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title ColorFul iGameCenter IOCTL ene.sys sub_140001AF0 untrusted pointer dereference
First Time appeared Colorful
Colorful igamecenter
Weaknesses CWE-822
CPEs cpe:2.3:a:colorful:igamecenter:*:*:*:*:*:*:*:*
Vendors & Products Colorful
Colorful igamecenter
References
Metrics cvssV2_0

{'score': 6.8, 'vector': 'AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

Colorful Igamecenter
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T18:30:09.358Z

Reserved: 2026-09-21T13:44:57.046Z

Link: CVE-2026-94403

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T19:17:19.867

Modified: 2026-09-21T19:17:19.867

Link: CVE-2026-94403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:30:15Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference