Heap-Based Buffer Overflow in VS Revo Uninstaller by VS Revo Group
CVE-2026-12193

8.5HIGH

Key Information:

Vendor

Vs Revo

Vendor
CVE Published:
14 June 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-12193?

A vulnerability exists within the VS Revo RevoUninstaller versions 2.5.x and 2.6.x. The issue is tied to the IOCtl_Handler function in the RevoDetector.sys driver, which is susceptible to heap-based buffer overflow. This manipulation requires local access, making the threat vector limited to users with local system access. An exploit for this vulnerability is publicly available, signaling an immediate need for users to upgrade to version 2.7.0 or higher to secure their systems and eliminate the risk associated with this flaw.

Affected Version(s)

RevoUninstaller 2.5.*

RevoUninstaller 2.6.*

RevoUninstaller 2.7.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jordanhiggins (VulDB User)
.