CVE-2026-29923Disclosure

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged users to map arbitrary physical memory into their address space and modify critical kernel structures.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-13: 2Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-04-13: 2PoC Mentioned / Linked · 2026-05-15: 1Exploit Tool / Code · 2026-04-13: 2Exploit Tool / Code · 2026-05-15: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-13: 2Technical Details · 2026-05-15: 104-0904-1305-15
Signal classification3 categories
Disclosure
240.0%
PoC
240.0%
Exploit
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-132
Exploit1PoC1
2026-05-151
PoC1
Full discourse5 posts
  • Mr. OS@ksg93rd
    Exploit

    #exploit #Kernel_Security 1⃣ Multiple vulnerabilities in AppArmor https://cdn2.qualys.com/advisory/2026/03/10/crack-armor.txt // AppArmor + Sudo + Postfix = root 2⃣ CVE-2026-29923: LPE Attack via pstrip64.sys https://github.com/athenasec16/CVE-2026-29923 // pstrip64.sys - legacy kernel-mode component. While its legitimate purpose is to enable advanced graphics card display tweaking, its deep system privileges make it a highly attractive target for attackers..

    Post summary

    The text announces a PoC and functional exploit for CVE‑2026‑29923, an LPE vulnerability via pstrip64.sys, alongside a separate advisory for multiple AppArmor flaws, indicating exploitation code is publicly available.

    140912701
    3.3K followersView on X
  • Tal Hagag@TalHagag16
    PoC

    A new BYOVD vulnerability (CVE-2026-29923) was discovered in pstrip64.sys driver. I just published a complete deep-dive on my GitHub covering the entire exploit lifecycle. #CyberSecurity #Vulnerability #LPE #BYOVD #WindowsSecurity #CVE #RedTeam #infosec https://github.com/athenasec16/CVE-2026-29923

    Post summary

    The post announces a new BYOVD vulnerability (CVE‑2026‑29923) and shares a GitHub deep‑dive, effectively revealing a proof‑of‑concept; no evidence of active exploitation or patches is provided.

    12051170
    2 followersView on X
  • Blue Team News@blueteamsec1
    PoC

    CVE-2026-29923 - Local Privilege Escalation Attack via pstrip64.sys http://dlvr.it/TSYNV4 #cyber #threathunting #infosec

    Post summary

    A tweet highlights CVE‑2026‑29923 as a local privilege escalation vulnerability in pstrip64.sys, likely sharing a PoC via the provided link, while offering no evidence of active exploitation or patch status.

    01042556
    56.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29923 The pstrip64.sys driver in EnTech Taiwan PowerStrip &lt;=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged u… https://www.cve.org/CVERecord?id=CVE-2026-29923 ----- Traducción: CVE-2026-29923 El … http://infoflow.cloud`

    Post summary

    The post discloses CVE‑2026‑29923, a local privilege escalation flaw in EnTech Taiwan PowerStrip’s pstrip64.sys driver that allows crafted IOCTL requests to gain SYSTEM privileges.

    0000036
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29923 The pstrip64.sys driver in EnTech Taiwan PowerStrip &lt;=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged u… https://www.cve.org/CVERecord?id=CVE-2026-29923

    Post summary

    CVE-2026-29923 discloses a local privilege escalation in EnTech Taiwan PowerStrip's pstrip64.sys driver (version <=3.90.736) via a crafted IOCTL request, allowing users to elevate to SYSTEM.

    00000175
    57.0K followersView on X

Explore more