CVE-2026-19189
PowerISO vulnerability analysis and mitigation

Overview

CVE-2026-19189 is a local privilege escalation vulnerability in Power Software PowerISO 9.3.0.0, caused by improper privilege management in the kernel driver component scdemu.sys (C:\Windows\System32\drivers\scdemu.sys). The flaw allows a local, low-privileged user to escalate privileges on the affected Windows system. It was published on August 7, 2026, with the CVE status listed as "Deferred." The vulnerability carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory, VulDB).

Technical details

The root cause is classified under CWE-266 (Incorrect Privilege Assignment) and CWE-269 (Improper Privilege Management), residing in the scdemu.sys kernel driver installed by PowerISO. The vulnerability enables local privilege escalation via arbitrary registry write or deletion operations exposed through the driver's IOCTL interface, allowing a low-privileged user to manipulate kernel-level resources. Exploitation requires only local access with standard user privileges and no user interaction. A technical write-up detailing the exploitation mechanism — specifically arbitrary registry write/deletion — is publicly referenced (winslow1984 write-up, VulDB).

Impact

Successful exploitation grants a local attacker full control over the vulnerable system, with high impact to confidentiality, integrity, and availability. An attacker with standard user privileges can escalate to administrative or SYSTEM-level access, enabling them to install malware, modify system configurations, access sensitive data, disable security controls, or establish persistence. While the scope is limited to the local system (no subsequent system impact in CVSS v4), administrative access could facilitate lateral movement in environments where credential reuse or shared resources are present (GitHub Advisory, VulDB).

Exploitability

A public proof-of-concept exploit has been released, as confirmed by the CVSS v4 exploit maturity rating of "Proof of Concept" and the NVD SSVC exploitation classification of "poc" (GitHub Advisory, VulDB). The EPSS score is approximately 0.111% (2nd percentile), indicating a currently low probability of active exploitation within 30 days. No in-the-wild exploitation or threat actor attribution has been reported at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vendor did not respond to early disclosure attempts.

Exploitation steps

  1. Reconnaissance: Identify target Windows systems with PowerISO 9.3.0.0 installed, confirming the presence of C:\Windows\System32\drivers\scdemu.sys.
  2. Obtain local access: Gain a foothold on the target system with a standard (low-privileged) user account — this could be via phishing, credential theft, or physical access.
  3. Interact with the vulnerable driver: Use a crafted application or script to send malicious IOCTL requests to the scdemu.sys kernel driver, exploiting its improper privilege management to perform arbitrary registry write or deletion operations.
  4. Manipulate registry for privilege escalation: Leverage the arbitrary registry write/delete capability to modify security-sensitive registry keys (e.g., service configurations, security descriptors) that enable elevation to SYSTEM or administrator privileges.
  5. Achieve elevated access: Execute commands or spawn processes under the elevated privilege context, achieving full administrative control of the system (winslow1984 write-up, VulDB).

Indicators of compromise

  • File System: Presence of C:\Windows\System32\drivers\scdemu.sys on systems where PowerISO 9.3.0.0 is installed; unexpected new executables or scripts in user-writable directories following privilege escalation.
  • Registry: Unauthorized modifications or deletions of security-sensitive registry keys, particularly under HKLM\SYSTEM\CurrentControlSet\Services\ or security descriptor entries; unexpected changes to service configurations.
  • Process: Processes spawned with SYSTEM or Administrator privileges from a standard user session context; unusual child processes originating from user-space applications interacting with kernel drivers.
  • Logs: Windows Security Event Log entries showing privilege use (Event ID 4672) or token elevation (Event ID 4624 with elevated logon type) for accounts not expected to hold such privileges; Windows System Event Log entries related to scdemu driver activity.

Mitigation and workarounds

The GitHub Advisory indicates a patch is available, though specific patched version numbers are not yet documented in the advisory (GitHub Advisory). Users should upgrade PowerISO to the latest available version and monitor the vendor's official site for a security update. As an interim workaround, restrict local access to systems running PowerISO 9.3.0.0 to trusted users only, and consider uninstalling PowerISO if it is not operationally required. Additionally, monitor systems for suspicious privilege escalation activity using endpoint detection tools.

Community reactions

The vulnerability was noted on Mastodon by security researcher @hugovalters shortly after disclosure (Mastodon). Coverage appeared across several vulnerability aggregation platforms including VulDB, CVEFeed, and The Hacker Wire. The vendor (Power Software) did not respond to the researcher's early disclosure attempts, which was noted as a concern in the advisory (VulDB, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related PowerISO vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-41992HIGH7.8
  • PowerISO logoPowerISO
  • cpe:2.3:a:poweriso:poweriso
NoNoDec 16, 2022
CVE-2021-21871HIGH7.8
  • PowerISO logoPowerISO
  • cpe:2.3:a:poweriso:poweriso
NoNoJun 29, 2021
CVE-2017-2823HIGH7.8
  • PowerISO logoPowerISO
  • cpe:2.3:a:poweriso:poweriso
NoYesMay 24, 2017
CVE-2017-2817HIGH7.8
  • PowerISO logoPowerISO
  • cpe:2.3:a:poweriso:poweriso
NoYesMay 24, 2017
CVE-2026-19189HIGH7.1
  • PowerISO logoPowerISO
  • cpe:2.3:a:poweriso:poweriso
NoNoAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management