CVE-2026-12193
Description
A heap-based buffer overflow in RevoDetector.sys driver in RevoUninstaller 2.5.x/2.6.x allows local attackers to escalate privileges via a crafted IOCTL request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A heap-based buffer overflow in RevoDetector.sys driver in RevoUninstaller 2.5.x/2.6.x allows local attackers to escalate privileges via a crafted IOCTL request.
Vulnerability
A heap-based buffer overflow vulnerability exists in the IOCtl_Handler function within the RevoDetector.sys driver of RevoUninstaller versions 2.5.x and 2.6.x (up to 2.6.8). The driver is loaded when the Revo Uninstaller Helper service is enabled. The overflow occurs in the Non-Paged pool when processing a specially crafted IOCTL request, leading to memory corruption.
Exploitation
Exploitation requires local access to the system and the RevoDetector.sys driver to be loaded (i.e., the Revo Uninstaller Helper must be enabled). An attacker sends a malicious IOCTL to the driver, triggering a Non-Paged pool overflow. This overflow allows the attacker to achieve arbitrary read and write primitives in kernel memory. Using these primitives, the attacker can steal the system token and escalate privileges to NT AUTHORITY\SYSTEM. The exploit is publicly available [1] but is noted to be unstable, with approximately a 90% success rate and a risk of system crash.
Impact
Successful exploitation grants the attacker local privilege escalation to SYSTEM level, providing full control over the affected Windows system. The attacker can execute arbitrary code with kernel privileges, install programs, view/change data, or create new accounts with full user rights.
Mitigation
The vendor has addressed this vulnerability in RevoUninstaller version 2.7.0. Users are strongly advised to upgrade to this version or later. No official workaround is available; however, disabling the Revo Uninstaller Helper service (which loads the vulnerable driver) may reduce exposure. The driver is currently signed and not on the Microsoft block list, so it could be used in a BYOVD (Bring Your Own Vulnerable Driver) attack scenario [1].
AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: 2.5.x, 2.6.x
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
10- github.com/Kalagious/RevoDetectorExploit/tree/masternvd
- jordanhiggins.blog/revouninstaller-pool-overflow-exploit/nvd
- vandalsuidaho-my.sharepoint.com/:w:/g/personal/higg2059_vandals_uidaho_edu/IQAMHgdfpRAkSqDsoFVswIYNAXjPVFz-admcJyl5ITzYhu0nvd
- vuldb.com/cve/CVE-2026-12193nvd
- vuldb.com/submit/829132nvd
- vuldb.com/submit/829133nvd
- vuldb.com/vuln/370839nvd
- vuldb.com/vuln/370839/ctinvd
- www.revouninstaller.com/start-freeware-download/nvd
- youtu.be/JR0KPjWRTnsnvd
News mentions
0No linked articles in our index yet.