CVE-2026-8049 PUBLISHED

CVE-2026-8049

Assigner: certcc
Reserved: 06.05.2026 Published: 17.06.2026 Updated: 18.06.2026

In SignalRGB versions prior to 1.3.7.0, the \.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in overly permissive default access control, allowing any authenticated local user to obtain a handle to the device and issue privileged IOCTLs.

Product Status

Vendor SignalRGB
Product SignalRGB kernel driver
Versions
  • affected from 0 to 1.3.7.0 (excl.)

References

Problem Types

  • CWE-284