CVE-2026-58583 Details
Description
FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at \Device\PhysicalMemory. Fixed in version 1.0.7.6. The fixed driver is currently available in the Windows 11 25H2 HLK (Hardware Lab Kit). The fixed driver may be available through Windows Update or from Lenovo directly.
A local privilege escalation vulnerability has been identified in the FluxInk Color Management Driver (TcnPeripheral64.sys) version 1.0.7.2. This vulnerability allows standard user accounts to perform arbitrary physical memory mapping at \Device\PhysicalMemory, with read and write permissions. The issue arises from the driver's IOCTL handler, which accepts user-supplied physical addresses and sizes without proper validation. Exploiting this vulnerability enables unauthorized users to access and modify kernel memory, steal process tokens, and bypass security measures such as antivirus or endpoint detection and response tools.
Users are advised to uninstall or disable the TcnPeripheral64.sys driver. If the driver is needed, it can be reinstalled from the Windows 11 25H2 Hardware Lab Kit, where the vulnerability has been patched. Alternatively, the driver can be blocked from loading using Windows Defender Application Control policies or by restricting access to the \.\SPBTESTTOOL device object.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/b3s3da/TcnPeripheral64_PoC | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://github.com/b3s3da/TcnPeripheral64_PoC/security/advisories/GHSA-x4rw-h4v2-v83h | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-188-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | |
| https://www.cve.org/CVERecord?id=CVE-2026-58583 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |