Executive brief
SignalRGB is a Windows application used to control lighting and monitor hardware performance. A security flaw in its system driver allows any logged-in user to gain unauthorized access to sensitive hardware controls. This could allow a malicious actor to interfere with system hardware or bypass security protections on the computer.
Technical details
The SignalRGB kernel driver (SignalIo.sys) creates the \\.\SignalIo device object without an explicit SDDL security descriptor and without the FILE_DEVICE_SECURE_OPEN flag. This results in an overly permissive default Discretionary Access Control List (DACL), enabling any authenticated local user to obtain a handle to the device. Once a handle is obtained, an attacker can issue privileged Input/Output Control (IOCTL) commands, including reading and writing to the PCI configuration space of system devices. The vulnerability is remediated in version 1.3.7.0, which implements a two-phase caller verification gate (image name allowlisting and Authenticode signature verification) during device creation.
Affected products
- SignalRGB SignalRGB kernel driver prior to 1.3.7.0
Timeline
- 2026-03-25: other: Vendor notified
- 2026-06-17: disclosed: Vulnerability note published by CERT/CC
- 2026-06-17: advisory
- 2026-06-17: patched: Remediated in version 1.3.7.0