8.5
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version 2.7.0 is sufficient to fix this issue. It is recommended to upgrade the affected component.
AI Analysis
Heap-based buffer overflow vulnerability in RevoUninstaller's RevoDetector.sys library, allowing local attackers to execute arbitrary code via the IOCtl_Handler function.
Basic Information
ID
CVE-2026-12193
Source
VulDB
Published
Jun 14, 2026 at 23:30
Affected Product
Vendor
VS Revo
Product
RevoUninstaller
Version
2.5.*
Affected Versions
VS Revo RevoUninstaller 2.5.*
VS Revo RevoUninstaller 2.6.*
VS Revo RevoUninstaller 2.6.*
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
VS Revo
Product
RevoUninstaller
Version
2.5.x, 2.6.x
References
- vuldb.com /vuln/370839
- vuldb.com /vuln/370839/cti
- vuldb.com /cve/CVE-2026-12193
- vuldb.com /submit/829132
- vuldb.com /submit/829133
- jordanhiggins.blog /revouninstaller-pool-overflow-exploit/
- github.com /Kalagious/RevoDetectorExploit/tree/master
- www.revouninstaller.com /start-freeware-download/
- vandalsuidaho-my.sharepoint.com /:w:/g/personal/higg2059_vandals_uidaho_edu/IQAMHgdfpRAkSqDsoFVswIYNAXjPVFz-admcJyl5ITzYhu0
- youtu.be /JR0KPjWRTns