PT-2026-98346 · Unknown · Argus Monitor

·

CVE-2026-79417

·

Published

2026-09-25

·

Updated

2026-09-29

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Argus Monitor (affected versions not specified)
Description An exposed IOCTL allows unprivileged users to disable x86 MONITOR and MWAIT instructions used by Hyper-V and other kernel components, which triggers a HYPERVISOR ERROR bugcheck. Accessing this IOCTL requires exploiting a TOCTOU (Time-of-Check to Time-of-Use) bug, which is a race condition where a system checks a condition and then uses the result, but the condition changes between the check and the use. This issue is attributed to poor documentation of the SeLocateProcessImageName() function. The driver employs a security through obscurity encryption scheme for its IOCTLs using a SHA-256 KDF-derived XOR keystream and a CRC16 Checksum.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Time Of Check To Time Of Use

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79417

Affected Products

Argus Monitor