2.3
CVE-2026-19382
- EPSS 0.12%
- Veröffentlicht 10.08.2026 00:45:09
- Zuletzt bearbeitet 13.08.2026 20:17:21
- CVE-Watchlists
- Unerledigt
Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAlmico
≫
Produkt
Speedfan
Version
4.52
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.02 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 1.8 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 2.3 | 0.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
|
| cna@vuldb.com | 1.4 | 2.5 | 2.9 |
AV:L/AC:L/Au:M/C:N/I:N/A:P
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
CWE-404 Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.
https://vuldb.com/vuln/387275
https://vuldb.com/vuln/387275/cti
https://vuldb.com/cve/CVE-2026-19382
https://vuldb.com/submit/866833
https://drive.google.com/file/d/18ocvgZ9aYGpaqMuojNH1jzVpQ1AJBI7d/view?usp=sharing