CVE-2026-90493: Tonec Internet Download Manager Kernel Driver idmwfp.sys access control
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Windows systems running Tonec Internet Download Manager with the idmwfp.sys kernel-driver component are affected through version 6.42 Build 63. Exploitation requires local access, so it is not described as remotely exploitable.
What level of access does an attacker need?
An attacker needs local access and low privileges. No user interaction is required, and successful exploitation can affect confidentiality, integrity, and availability across a changed security scope.
Is public exploit code available?
Yes. The exploit is reported as public and may be used, increasing the practical risk on affected local systems.
Is a vendor fix available?
The available information does not identify a fix or a patched version. The vendor was contacted before disclosure but did not respond.