CVE-2026-79417 Details
Description
Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.
A local denial-of-service vulnerability has been identified in the ArgusMonitor.sys driver for Argotronic eGbR ArgusMonitor versions through 7.4.02. The issue arises from improper access control that allows low-privileged users to bypass device handle access restrictions. This is achieved through a time-of-check-to-time-of-use (TOCTOU) condition in the IRP_MJ_CREATE handler, enabling the manipulation of the process image path to evade security checks. Exploitation involves sending a crafted IOCTL 0x9C4024A8 request, which disables critical CPU power-management features, leading to system instability and a bugcheck.
Users are advised to update to the patched version of ArgusMonitor, which is available on the Argus Monitor website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/ | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Argotronic eGbR ArgusMonitor | <= 7.4.02 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion