CVE-2026-97732: Medium severity IRONMACE Ironshield vulnerability

Published Sep 25, 2026
·
Updated

IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WINCERTIFICATE data ("IRONMACE Co., Ltd." and "DigiCert Trusted Root G4") instead of parsing and validating the PKCS signature data. As a result, a local unprivileged attacker may bypass this via crafted certificate data and obtain access to privileged IOCTL functionality.

Affected Software

1 affected component
IRONMACE Ironshield=1.0.0.167

Event History

Sep 25, 2026
CVE Published
via MITRE·03:29 AM
Data Sourced
via MITRE·03:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems with IRONMACE Ironshield 1.0.0.167 and its tvk.sys kernel-mode driver installed are exposed. Exploitation requires local access, but the attacker does not need prior privileges or user interaction.

2

What does an attacker need to exploit it?

An attacker needs to run a client executable locally and provide crafted WIN_CERTIFICATE data containing the expected publisher and root-certificate strings. The driver checks those strings rather than parsing and validating the PKCS signature data.

3

What access could exploitation provide?

A successful bypass can give an unprivileged local attacker access to privileged IOCTL functionality exposed by the kernel-mode driver.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203