Record summary

CVE-2026-8501 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.

Description

Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 1, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List*affected

Proofs of concept

1

Repository PoCs

GitHubBlackSnufkin/BYOVDRepository PoCby BlackSnufkinStars: 900Not analyzed140 files

2.7 MiB · linked to 4 vulnerabilities

GitHub

PoC details

References

5