kb.cert.org
https://kb.cert.org/vuls/id/158530 CVE-2026-8501
HIGH
PC Tools Internet Security PCTCore64.sys Exposed IOCTL with Insufficient Access Control
Record summary
CVE-2026-8501 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.
Description
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 1, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PC Tools Internet SecurityBrowse Symantec / PC Tools Internet Security | CVE List | * | affected |
Proofs of concept
1Repository PoCs
GitHubBlackSnufkin/BYOVDRepository PoCby BlackSnufkinStars: 900Not analyzed140 files
References
5learn.microsoft.com
https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules learn.microsoft.com
https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-8501 kb.cert.org
https://www.kb.cert.org/vuls/id/158530