๐Ÿ” CVE Alert

CVE-2026-97732

MEDIUM 5.1
CVSS Score
5.1
EPSS Score
0.0%
EPSS Percentile
0th

IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and "DigiCert Trusted Root G4") instead of parsing and validating the PKCS signature data. As a result, a local unprivileged attacker may bypass this via crafted certificate data and obtain access to privileged IOCTL functionality.

CWE CWE-347
Vendor ironmace
Product ironshield
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for ironmace ironshield

Be the first to know when new medium vulnerabilities affecting ironmace ironshield are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

IRONMACE / Ironshield
1.0.0.167

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/hseoa/ironshield-analysis store.steampowered.com: https://store.steampowered.com/eula/2016590_eula_0