
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19189 is a local privilege escalation vulnerability in Power Software PowerISO 9.3.0.0, caused by improper privilege management in the kernel driver component scdemu.sys (C:\Windows\System32\drivers\scdemu.sys). The flaw allows a local, low-privileged user to escalate privileges on the affected Windows system. It was published on August 7, 2026, with the CVE status listed as "Deferred." The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, VulDB).
The root cause is classified under CWE-266 (Incorrect Privilege Assignment) and CWE-269 (Improper Privilege Management), residing in the scdemu.sys kernel driver installed by PowerISO. The vulnerability enables local privilege escalation via arbitrary registry write or deletion operations exposed through the driver's IOCTL interface, allowing a low-privileged user to manipulate kernel-level resources. Exploitation requires only local access with standard user privileges and no user interaction. A technical write-up detailing the exploitation mechanism — specifically arbitrary registry write/deletion — is publicly referenced (winslow1984 write-up, VulDB).
Successful exploitation grants a local attacker full control over the vulnerable system, with high impact to confidentiality, integrity, and availability. An attacker with standard user privileges can escalate to administrative or SYSTEM-level access, enabling them to install malware, modify system configurations, access sensitive data, disable security controls, or establish persistence. While the scope is limited to the local system (no subsequent system impact in CVSS v4), administrative access could facilitate lateral movement in environments where credential reuse or shared resources are present (GitHub Advisory, VulDB).
A public proof-of-concept exploit has been released, as confirmed by the CVSS v4 exploit maturity rating of "Proof of Concept" and the NVD SSVC exploitation classification of "poc" (GitHub Advisory, VulDB). The EPSS score is approximately 0.111% (2nd percentile), indicating a currently low probability of active exploitation within 30 days. No in-the-wild exploitation or threat actor attribution has been reported at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vendor did not respond to early disclosure attempts.
C:\Windows\System32\drivers\scdemu.sys.scdemu.sys kernel driver, exploiting its improper privilege management to perform arbitrary registry write or deletion operations.C:\Windows\System32\drivers\scdemu.sys on systems where PowerISO 9.3.0.0 is installed; unexpected new executables or scripts in user-writable directories following privilege escalation.HKLM\SYSTEM\CurrentControlSet\Services\ or security descriptor entries; unexpected changes to service configurations.scdemu driver activity.The GitHub Advisory indicates a patch is available, though specific patched version numbers are not yet documented in the advisory (GitHub Advisory). Users should upgrade PowerISO to the latest available version and monitor the vendor's official site for a security update. As an interim workaround, restrict local access to systems running PowerISO 9.3.0.0 to trusted users only, and consider uninstalling PowerISO if it is not operationally required. Additionally, monitor systems for suspicious privilege escalation activity using endpoint detection tools.
The vulnerability was noted on Mastodon by security researcher @hugovalters shortly after disclosure (Mastodon). Coverage appeared across several vulnerability aggregation platforms including VulDB, CVEFeed, and The Hacker Wire. The vendor (Power Software) did not respond to the researcher's early disclosure attempts, which was noted as a concern in the advisory (VulDB, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."