Junglewise Threat Intelligence

CVE-2026-30266: DeepCool DeepCreative insecure permissions in service binaries

CVE-2026-30266 · Severity: high · CVSS 7.8 · Published 2026-04-20

Executive brief

DeepCool DeepCreative, a software suite used for managing computer hardware components, contains a security flaw due to improper file permissions. A local user on the computer could replace legitimate system files with malicious ones, allowing them to take full control of the machine. This could lead to the theft of sensitive data or the installation of persistent malware.

Technical details

An insecure inherited permissions vulnerability (CWE-277) exists in DeepCool DeepCreative versions up to and including 1.2.12. The software installs services that run with NT AUTHORITY\SYSTEM privileges but fails to restrict write access to the underlying executable files. A local, unprivileged attacker can exploit this by overwriting a service binary with a malicious file. When the service starts or restarts, the attacker's code is executed with elevated system-level privileges. While the CVSS vector suggests some user interaction (UI:R), the primary mechanism is a local privilege escalation via file system permission misconfiguration.

Affected products

  • DeepCool DeepCreative 1.2.12 and earlier

Timeline

  • 2025-12: disclosed: Vulnerability discovered by Uncle-Hash
  • 2026-04-20: advisory: Initial CVE publication

References