Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kncrjnet

#31871of 57,493
8.8Total CVSS
Vulnerabilities · 1
PT-2026-90783
8.8
2026-09-13
Tonec · Internet Download Manager · CVE-2026-90493
**Name of the Vulnerable Software and Affected Versions** Tonec Internet Download Manager versions prior to 6.42 Build 64 **Description** An improper access control issue exists in the `idmwfp.sys` kernel driver of Tonec Internet Download Manager on Windows. The driver exposes the `.IDMWFP` device interface to authenticated local users with generic access. Specifically, the IOCTL `0x12C028` handler processes registry-operation subcommands `0x0C` through `0x0F` without authenticating the caller or enforcing registry permissions. This allows a low-privileged local authenticated user to read, create, modify, and delete arbitrary registry values under HKLM and HKU. Such manipulation can lead to Local Privilege Escalation to SYSTEM, high-privilege persistence, and unauthorized modification of system configurations, compromising system confidentiality, integrity, and availability. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.