CVE-2026-94403: Untrusted Pointer Dereference in ColorFul iGameCenter
A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
This vulnerability in ColorFul iGameCenter 1.0.3.4 arises from an untrusted pointer dereference in the IOCTL Handler component within the ene.sys library, specifically in function sub_140001AF0. The flaw allows a local attacker with limited privileges to execute an attack without user interaction. Exploit code is publicly available, increasing the risk of exploitation. The vendor was notified but has not issued any response or patch.
Potential Impact
Successful exploitation can lead to severe consequences as indicated by the CVSS 4.0 score of 9.3, which includes high impact on confidentiality, integrity, availability, and security controls. The attack requires local access and low privileges but does not require user interaction. The presence of public exploit code increases the risk of exploitation, potentially allowing attackers to compromise system stability or security.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor, as they have not responded to the disclosure. Users should restrict local access to trusted personnel only and monitor for any suspicious activity related to the vulnerable component. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance if it becomes available.
CVE-2026-94403: Untrusted Pointer Dereference in ColorFul iGameCenter
Description
A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 9.3critical
Affected software
ColorFul
iGameCenter
cpe:2.3:a:colorful:igamecenter:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in ColorFul iGameCenter 1.0.3.4 arises from an untrusted pointer dereference in the IOCTL Handler component within the ene.sys library, specifically in function sub_140001AF0. The flaw allows a local attacker with limited privileges to execute an attack without user interaction. Exploit code is publicly available, increasing the risk of exploitation. The vendor was notified but has not issued any response or patch.
Potential Impact
Successful exploitation can lead to severe consequences as indicated by the CVSS 4.0 score of 9.3, which includes high impact on confidentiality, integrity, availability, and security controls. The attack requires local access and low privileges but does not require user interaction. The presence of public exploit code increases the risk of exploitation, potentially allowing attackers to compromise system stability or security.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor, as they have not responded to the disclosure. Users should restrict local access to trusted personnel only and monitor for any suspicious activity related to the vulnerable component. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance if it becomes available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-21T13:44:57.046Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab17bd055bf5e2cf550c23e
Added to database: 09/21/2026, 18:47:44 UTC
Last enriched: 09/21/2026, 19:01:30 UTC
Last updated: 09/22/2026, 00:48:05 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.