Junglewise Threat Intelligence

CVE-2026-94403: ColorFul iGameCenter untrusted pointer dereference in IOCTL handler

CVE-2026-94403 · Severity: high · CVSS 8.8 · Published 2026-09-21

Executive brief

ColorFul iGameCenter is a gaming peripheral control software that manages hardware devices through system drivers. A flaw in the IOCTL handler allows local attackers to dereference invalid memory pointers, potentially causing system crashes or enabling privilege escalation. Public exploits are available, though the vendor has not responded to disclosure attempts.

Technical details

An untrusted pointer dereference vulnerability exists in the ene.sys driver's IOCTL handler (function sub_140001AF0) in iGameCenter 1.0.3.4. The flaw is reachable only by local attackers with the ability to send crafted IOCTL requests. Exploitation can lead to denial of service or arbitrary code execution at kernel privilege level.

Affected products

  • ColorFul iGameCenter 1.0.3.4

Timeline

  • 2026-09-21: disclosed

References

Related threats