{"id":"CVE-2026-97732","published":"2026-09-25T04:17:50.537","lastModified":"2026-09-25T14:17:26.387","description":"IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data (\"IRONMACE Co., Ltd.\" and \"DigiCert Trusted Root G4\") instead of parsing and validating the PKCS signature data. As a result, a local unprivileged attacker may bypass this via crafted certificate data and obtain access to privileged IOCTL functionality.","cvssScore":5.1,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-347"],"vendors":[],"products":[],"references":[{"url":"https://github.com/hseoa/ironshield-analysis","tags":[]},{"url":"https://store.steampowered.com/eula/2016590_eula_0","tags":[]}],"exploitRefs":[{"url":"https://github.com/hseoa/ironshield-analysis","tags":[]}],"hasPoc":true,"ai":null}