Executive brief
ColorFul iGameCenter is a gaming peripheral control software that manages hardware devices through system drivers. A flaw in the IOCTL handler allows local attackers to dereference invalid memory pointers, potentially causing system crashes or enabling privilege escalation. Public exploits are available, though the vendor has not responded to disclosure attempts.
Technical details
An untrusted pointer dereference vulnerability exists in the ene.sys driver's IOCTL handler (function sub_140001AF0) in iGameCenter 1.0.3.4. The flaw is reachable only by local attackers with the ability to send crafted IOCTL requests. Exploitation can lead to denial of service or arbitrary code execution at kernel privilege level.
Affected products
- ColorFul iGameCenter 1.0.3.4
Timeline
- 2026-09-21: disclosed