CVE-2026-8501: High severity PC Tools PCTCore64.sys (PC Tools Internet Security) vulnerability

Published Jun 1, 2026
·
Updated

Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.

Affected Software

1 affected component
PC Tools PCTCore64.sys (PC Tools Internet Security)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove PCTCore64.sys (PCTCoreDriver) from your environment.

    Uninstall or remove the PCTCore64.sys driver (PCTCoreDriver) from systems where it is installed if the driver is not required.

  2. Configuration

    Modify the device object's security descriptor to prevent user-mode processes from opening the PCTCoreDriver device and invoking privileged IOCTL handlers; grant access only to Administrators and SYSTEM.

    PCTCoreDriver WDM device interface device security descriptor / access control = restrict access to Administrators and SYSTEM
  3. Compensating control

    Prevent non-privileged users from loading or accessing the PCTCore64.sys driver (for example, block loading of the driver via endpoint control or enforce driver-loading policies) and restrict local access to systems where the driver is installed.

  4. Operational

    Audit and inventory endpoints for the presence of PCTCore64.sys / PCTCoreDriver; isolate or remediate affected systems, remove the driver where appropriate, and monitor for signs of attempted or successful exploitation of the PCTCoreDriver device interface.

Event History

Jun 1, 2026
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Jun 29, 58424
Event
via FIRST·03:21 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-8501?

CVE-2026-8501 has a high severity rating of 7.8 based on the CVSS 3.1 scoring system.

2

How do I fix CVE-2026-8501?

To fix CVE-2026-8501, ensure that you update or patch the PC Tools PCTCore64.sys driver as soon as an update is provided by the vendor.

3

What causes CVE-2026-8501?

CVE-2026-8501 is caused by improper access control in the PCTCore64.sys Windows kernel driver that allows unauthorized access to privileged IOCTL handlers.

4

Who could be affected by CVE-2026-8501?

Local attackers with the ability to access or load the affected driver within PC Tools Internet Security could exploit CVE-2026-8501.

5

What are the potential impacts of CVE-2026-8501?

Exploitation of CVE-2026-8501 could lead to unauthorized access to sensitive data and allow attackers to execute arbitrary code with elevated privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203