CVE-2026-79417
Received Received - Intake

Improper Access Control in ArgusMonitor.sys

Vulnerability report for CVE-2026-79417, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: MITRE

Description

Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
argotronic argusmonitor to 7.4.02 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-79417 is a local denial-of-service vulnerability in ArgusMonitor.sys affecting versions 7.4.02 and earlier. It involves improper access control where low-privileged users can exploit a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL request (0x9C4024A8) to bypass device handle restrictions. The flaw allows disabling CPU power-management via the WRMSR instruction targeting MSR 0xC0010015 (HWCR) on AMD systems, causing a system crash due to illegal MONITOR/MWAIT opcode execution in Hyper-V.

Detection Guidance

Detecting this vulnerability requires checking for the presence of ArgusMonitor.sys versions 7.4.02 or earlier. Inspect the driver file version and digital signature. Look for unusual IOCTL requests or WRMSR instruction usage in system logs. Monitor for system crashes with HYPERVISOR_ERROR 0x2001.

Impact Analysis

This vulnerability allows low-privileged users to crash the system by disabling CPU power-management features. On systems running Hyper-V, it can trigger a bugcheck (HYPERVISOR_ERROR 0x2001), leading to a denial-of-service condition. Exploitation requires local access and crafting a specific IOCTL payload.

Mitigation Strategies

Immediately update ArgusMonitor to the latest patched version released on September 24, 2026. Remove or disable the vulnerable driver ArgusMonitor.sys if not required. Restrict access to the driver device object to prevent unauthorized IOCTL requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79417. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart