PT-2026-50558 · Signalrgb · Signalrgb
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SignalRGB versions prior to 1.3.7.0
Description
The
.SignalIo device object is created without an explicit SDDL (Security Descriptor Definition Language) security descriptor and without FILE DEVICE SECURE OPEN. This configuration leads to overly permissive default access control, enabling any authenticated local user to obtain a handle to the device and issue privileged IOCTLs (Input/Output Control codes), which are used to communicate directly with device drivers.Recommendations
Update to version 1.3.7.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Signalrgb