Executive brief
A security vulnerability exists in Revo Uninstaller, a popular Windows utility used to remove unwanted software and traces of programs. A flaw in one of its background components could allow a person with limited access to a computer to gain full administrative control. This could lead to the theft of sensitive data, the installation of malicious software, or a complete system crash.
Technical details
A heap-based buffer overflow vulnerability exists in the IOCtl_Handler function within the RevoDetector.sys driver of VS Revo RevoUninstaller versions 2.5.x and 2.6.x (specifically up to 2.6.8). The flaw occurs when the driver is loaded (typically when the Revo Uninstaller Helper is enabled) and fails to properly validate input sizes during IOCTL handling. A local attacker with low privileges can exploit this non-paged pool overflow to achieve arbitrary read and write primitives. By manipulating system memory, the attacker can steal the SYSTEM token to elevate their privileges to the highest level on a Windows 11 system. A public exploit is available, though it may cause system instability (BSOD). The issue is resolved in version 2.7.0.
Affected products
- VS Revo Group Revo Uninstaller 2.5.x, 2.6.x (up to 2.6.8)
Timeline
- 2026-06-15: disclosed
- 2026-06-15: advisory
- 2026-06-15: patched: Fixed in version 2.7.0
References
- https://github.com/Kalagious/RevoDetectorExploit/tree/master
- https://jordanhiggins.blog/revouninstaller-pool-overflow-exploit/
- https://vandalsuidaho-my.sharepoint.com/:w:/g/personal/higg2059_vandals_uidaho_edu/IQAMHgdfpRAkSqDsoFVswIYNAXjPVFz-admcJyl5ITzYhu0?e=4Ywwza
- https://vuldb.com/cve/CVE-2026-12193
- https://vuldb.com/submit/829132
- https://vuldb.com/submit/829133
- https://vuldb.com/vuln/370839