PatchSiren

IRONMACE CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM IRONMACE CVE published 2026-09-25

CVE-2026-97732

A local unprivileged attacker may bypass authentication for privileged IOCTL functionality in IRONMACE Ironshield 1.0.0.167 due to improper validation of certificate data. This issue arises from the kernel-mode driver (tvk.sys) checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data instead of parsing and validating the PKCS signature data. As a result, an attacker can exploit [truncated]