CVE Explorer
CVE-2026-8501
Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to perform sensitive and privileged operations on the target system.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"CWE-782: Exposed IOCTL with Insufficient Access Control","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-782","description":"CWE-782 Exposed IOCTL with Insufficient Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"PC Tools Internet Security","vendor":"Symantec","versions":[{"status":"affected","version":"*"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"description":"CWE-782: Exposed IOCTL with Insufficient Access Control","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-782","description":"CWE-782 Exposed IOCTL with Insufficient Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"https://kb.cert.org/vuls/id/158530"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/cna/references/2
{"url":"https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/cna/references/0
{"url":"https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/cna/references/1
{"url":"https://www.kb.cert.org/vuls/id/158530"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:0dcded75b9f61772d46926a257053bb10789e228f68b2d4e2244d6333bfe14c1 · sha256:966608c01d33b071… · /containers/adp/1/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.