CVE-2026-8501
7.8 HIGHImproper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access t...
Published: 2026-06-01 · Last updated: 2026-06-01
Severity and scoring
- CVSS
- 7.8 HIGH
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-782
Description
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-8501
- [Other]https://kb.cert.org/vuls/id/158530
- [Other]https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules
- [Other]https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language
- [Other]https://www.kb.cert.org/vuls/id/158530