CVE-2026-97732: Ironmace Ironshield

Medium severity, CVSS 5.1. EPSS: 0.1% chance of exploitation in the next 30 days.

IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and "DigiCert Trusted Root G4") instead of parsing and validating the PKCS signature data. As a result, a local unprivileged attacker may bypass this via crafted certificate data and obtain access to privileged IOCTL functionality.

Affected products

  • Ironmace Ironshield: version 1.0.0.167 only

Published 2026-09-25. Last modified 2026-09-30.