CVE-2026-19189General

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-07); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-07: 1Mentions · 2026-08-09: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-09: 108-0708-09
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-071
General1
2026-08-091
Patch1
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-19189 - LPE in PowerISO 9.3.0.0 via scdemu.sys. Improper privilege management, local exploit public. CVSS 7.8. Unpatched - disable driver or update ASAP. #CVE #PowerISO #infosec https://www.valtersit.com/cve/CVE-2026-19189 #infosec #cybersecurity #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu

    Post summary

    CVE-2026-19189 is a local privilege escalation flaw in PowerISO 9.3.0.0 (scdemu.sys) with CVSS 7.8. It is unpatched; disabling the driver or updating is recommended.

    0000064
    1.0K followersView on X
  • SecNews@SecNews_GR
    General

    PowerISO CVE-2026-19189: Κίνδυνος τοπικής ανύψωσης δικαιωμάτων https://secn.ws/MwHNcw

    Post summary

    The headline reports that PowerISO’s CVE-2026-19189 poses a local privilege escalation risk, but offers no additional technical or operational details, PoCs, exploits, or mitigation information.

    00000160
    7.0K followersView on X

Explore more