CVE-2020-12446PoC(gskill / trident_z_lighting_control)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for gskill trident_z_lighting_control systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The ene.sys driver in G.SKILL Trident Z Lighting Control through 1.00.08 exposes mapping and un-mapping of physical memory, reading and writing to Model Specific Register (MSR) registers, and input from and output to I/O ports to local non-privileged users. This leads to privilege escalation to NT AUTHORITY\SYSTEM.

3.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trident_z_lighting_control

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 1 signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
trident_z_lighting_control

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-17: 2PoC Mentioned / Linked · 2026-08-17: 2Exploit Tool / Code · 2026-08-17: 2Technical Details · 2026-08-17: 108-17
Signal classification1 categories
PoC
2100.0%
Referenced assets5 URLs
Full discourse2 posts
  • _SiCk@encrypted_past
    PoC

    We chained two vuln drivers - credits given where they're due. funny how a known vuln driver with a CVE from 2020 still doesn't land in the driver blacklist on the most up to date windows patches. @FAMASoon here's what you do. CVE-2020-12446, discovered by @ihack4falafel, exploit technique by https://github.com/Xacone The chain isn't what matters, it's showcasing the primitives. #ChainThem #SeDebugTheseNuts https://github.com/0xdeadbeefnetwork/KKYUMPoC

    Post summary

    The post shares a proof‑of‑concept showing how to chain a known 2020 driver vulnerability (CVE-2020-12446) with exploit technique references, but it does not report active exploitation, patches, or technical details.

    315074455.1K
    4.3K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 2020 tarihli Windows sürücü açığı yeniden gündemde G.SKILL Trident Z Lighting Control yazılımına ait ene.sys sürücüsündeki CVE-2020-12446 açığı, Windows üzerinde yerel yetki yükseltme (LPE) amacıyla yeniden kullanıldı. Güvenlik araştırmacıları, açığı bulunan sürücüleri zincirleyerek fiziksel bellek okuma/yazma, MSR ve I/O erişimi gibi kernel seviyesinde primitive'ler elde etti ve sonunda NT AUTHORITY\SYSTEM yetkisine ulaştı. Araştırmacılara göre asıl dikkat çekici nokta, zincirin kendisinden ziyade bu tür vulnerable signed driver'ların modern Windows sistemlerinde hala güçlü kernel primitive'leri sağlayabilmesi. Düşük yetkili kullanıcı -> Kernel primitive -> SYSTEM Bilinen PoC'ler: https://github.com/Xacone/Eneio64-Driver-Exploits https://github.com/enessakircolak/Windows-11-24h2-Kernel-Exploit https://github.com/S1lkys/Eneio64-LPE

    Post summary

    The post revisits CVE‑2020‑12446, a Windows driver local privilege‑escalation flaw, providing publicly available PoC code links and explaining the kernel‑level privilege‑escalation chain.

    0101381.5K
    2.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgskilltrident_z_lighting_control---

Explore more