CVE-2026-90503: Chengdu Qilu Technology Ludashi ComputerZ_x64.sys sub_11008 information disclosure
A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub11008 in the library ComputerZx64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to launch an attack locally and have high privileges. The issue is therefore most relevant on systems where an attacker or untrusted local user can obtain elevated access.
Is exploit code available?
Yes. The exploit has been published and may be used, increasing the practical risk for affected installations.
Which release is identified as affected?
The reported affected product is Chengdu Qilu Technology Ludashi version 6.1026.4715.714, specifically the ComputerZ_x64.sys library and its sub_11008 function.
Is a vendor fix available?
The available information does not identify a fix. The vendor was contacted early about the disclosure but did not respond.