CVE-2026-79417: Argotronic ArgusMonitor vulnerability
Published Sep 29, 2026
·Updated
Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRPMJCREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.
Affected Software
1 affected component
Argotronic ArgusMonitor<=7.4.02
Event History
Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
A local, low-privileged user can exploit it. The described impact is denial of service.
2
What does exploitation require?
The attacker needs local access, must race a time-of-check/time-of-use condition during IRP_MJ_CREATE, and then send a crafted IOCTL request with code 0x9C4024A8.
3
Which releases are affected?
ArgusMonitor 7.4.02 and earlier are identified as affected.