CVE-2026-19381 PUBLISHED

Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges management

Assigner: VulDB
Reserved: 09.08.2026 Published: 10.08.2026 Updated: 10.08.2026

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 8.5

Product Status

Vendor Kingston
Product FURY CTRL RGB Control Software
Versions
  • Version 2.0.65.0 is affected

Credits

  • Raulisr00t (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Improper Privilege Management CWE
  • Incorrect Privilege Assignment CWE