CVE-2026-82628: Colorful iGameCenter IOCTL Dispatch WinRing0x64.sys sub_11504 privileges management
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker must already have local access to the affected system. The vulnerability has low attack complexity and requires low privileges; no user interaction is required.
Which installations are known to be affected?
The affected product identified is Colorful iGameCenter version 2.0.0.81. The vulnerable code is in the WinRing0x64.sys driver’s IOCTL Dispatch component, specifically sub_11504.
What security impact could successful exploitation have?
The reported severity vector indicates high impacts to confidentiality, integrity, and availability, with scope changed. The flaw is an improper privilege-management issue triggered through manipulation of PhysicalAddress, AlignNumer, and AlignSize arguments.