CVE-2026-19382
Received Received - Intake

Memory Leak in Almico SpeedFan 4.52

Vulnerability report for CVE-2026-19382, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: VulDB

Description

A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
almico speedfan 4.52

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory leak in Almico Speedfan 4.52 caused by a flaw in the KiSystemCall64 function within the speedfan.sys library. It occurs due to improper handling of MSR Index. The issue allows local attackers to exploit it, leading to memory resource exhaustion. A public exploit is available, increasing the risk of real-world attacks.

Detection Guidance

Since this vulnerability is local and affects the MSR Index Handler in Speedfan.sys, detection would require checking for the presence of the vulnerable driver and analyzing memory usage patterns. No specific commands are provided in the context. Monitor for unusual memory consumption by speedfan.sys or unexpected system behavior.

Impact Analysis

If you use Almico Speedfan 4.52, this vulnerability could cause your system to run out of memory over time due to the memory leak. This may lead to performance degradation, crashes, or instability of the affected system. Since the attack requires local access, attackers would need prior access to your machine to exploit it.

Mitigation Strategies

Immediately uninstall or disable Almico Speedfan 4.52. Ensure no other applications rely on speedfan.sys. Apply any available vendor patches if released later. Restrict local user privileges to reduce attack surface. Monitor system logs for suspicious activity related to the driver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19382. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart