CVE-2026-19381
Received Received - Intake

Improper Privilege Management in Kingston FURY CTRL RGB Control Software

Vulnerability report for CVE-2026-19381, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: VulDB

Description

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
kingston fury_ctrl_rgb_control_software 2.0.65.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a security flaw in Kingston FURY CTRL RGB Control Software 2.0.65.0. It involves improper privilege management in the NTIOLib_KSFX.sys driver component due to an unknown function. The attack requires local access and has been publicly disclosed, increasing the risk of exploitation.

Detection Guidance

Since this vulnerability involves a local privilege escalation in the Kingston FURY CTRL RGB Control Software driver (NTIOLib_KSFX.sys), detection requires checking for the presence of vulnerable software or driver files on the system. Look for the driver file NTIOLib_KSFX.sys in system directories like C:\Windows\System32\drivers. Use commands such as 'dir /s NTIOLib_KSFX.sys' in Command Prompt or 'find / -name NTIOLib_KSFX.sys' in Linux to search for the file.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local access to gain elevated privileges on the system. This may lead to unauthorized control, data manipulation, or further compromise of the affected device.

Mitigation Strategies

Immediately uninstall the Kingston FURY CTRL RGB Control Software version 2.0.65.0 or later if available. Disable or remove the NTIOLib_KSFX.sys driver if it is present on the system. Restrict local user access to administrative privileges to limit potential exploitation. Monitor system logs for unusual activity related to privilege changes or driver loads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19381. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart