Untrusted Pointer Dereference in ColorFul iGameCenter Affects Local Systems
CVE-2026-94403

9.3CRITICAL

Key Information:

Vendor

Colorful

Vendor
CVE Published:
21 September 2026

What is CVE-2026-94403?

A vulnerability exists in ColorFul iGameCenter version 1.0.3.4 regarding an untrusted pointer dereference in the IOCTL Handler function sub_140001AF0 within the library ene.sys. This weakness can be exploited locally, potentially allowing attackers to manipulate system resources. The exploit code has been publicly released, highlighting the need for immediate attention. Despite early notifications, the vendor has not responded to address these security concerns.

Affected Version(s)

iGameCenter 1.0.3.4

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bigcat (VulDB User)
VulDB CNA Team
.