Heap-Based Buffer Overflow in VS Revo Uninstaller by VS Revo Group
CVE-2026-12193
Key Information:
- Vendor
Vs Revo
- Status
- Vendor
- CVE Published:
- 14 June 2026
Badges
What is CVE-2026-12193?
A vulnerability exists within the VS Revo RevoUninstaller versions 2.5.x and 2.6.x. The issue is tied to the IOCtl_Handler function in the RevoDetector.sys driver, which is susceptible to heap-based buffer overflow. This manipulation requires local access, making the threat vector limited to users with local system access. An exploit for this vulnerability is publicly available, signaling an immediate need for users to upgrade to version 2.7.0 or higher to secure their systems and eliminate the risk associated with this flaw.
Affected Version(s)
RevoUninstaller 2.5.*
RevoUninstaller 2.6.*
RevoUninstaller 2.7.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
