CVE-2026-8049 Details
Description
In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in overly permissive default access control, allowing any authenticated local user to obtain a handle to the device and issue privileged IOCTLs.
A vulnerability in the SignalRGB kernel driver, 'SignalIo.sys', prior to version 1.3.7.0, allows any authenticated local user to access privileged input/output control (IOCTL) commands. This issue arises because the 'SignalIo' device object is created without a proper security descriptor, leaving default access controls overly permissive. As a result, unprivileged user-mode processes can obtain handles to the device and issue commands that manipulate sensitive hardware operations.
Users are advised to update to SignalRGB version 1.3.7.0 or later, where this vulnerability has been addressed. Organizations should also consider implementing additional security measures to reduce exposure to such vulnerabilities, such as restricting administrative privileges and using application control solutions like Windows Defender Application Control.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 17, 2026CISA-ADP
Assessed Jun 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kb.cert.org/vuls/id/380058 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| SignalRGB | < 1.3.7.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 18, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | New CVE Received | [email protected] |
Volerion