Kernel-mode Driver Vulnerability in Ironshield by IRONMACE
CVE-2026-97732
5.1MEDIUM
What is CVE-2026-97732?
The Ironshield 1.0.0.167 by IRONMACE features a kernel-mode driver (tvk.sys) that incorrectly authenticates client executables. Instead of properly validating the PKCS signature data, it checks for specific publisher and root-certificate strings in WIN_CERTIFICATE data, which could allow a local unprivileged attacker to craft malicious certificate data. This weakness can lead to unauthorized access to sensitive privileged IOCTL functionalities, posing serious security implications.
Affected Version(s)
Ironshield Windows 1.0.0.167
