CVE-2026-8501
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the
CVSS
7.8
Alto
EPSS
0.2%
p6
KEV
—
Exploit Today
2
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-782
0.2%EPSS · 30 días0.2%
2026-07-042026-07-31
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.
- kb.cert.orghttps://kb.cert.org/vuls/id/158530
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language
- www.kb.cert.orghttps://www.kb.cert.org/vuls/id/158530
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-387647.8 ALT8.4%
——3An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys3dCVE-2026-387667.8 ALT6.8%
——2An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function9dCVE-2026-387657.8 ALT6.8%
——2An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys9dCVE-2019-25764—0.5%
——0**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.
Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.16dCVE-2026-94927.8 ALT1.4%
——0The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and writing physical memory and obtaining kernel-level privileges.19dCVE-2026-578517.8 ALT6.7%
——2MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can exploit the accessible device object through IOCTL handlers to manipulate kernel objects, tamper with kernel-mode callbacks, bypass Protected Process Light protections, and disable security software.23d