Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)

News

(1) An exposed IOCTL lets unprivileged users disable the x86 MONITOR & MWAIT instructions used by Hyper-V and other kernel components–triggering a HYPERVISOR_ERROR bugcheck. (2) Reaching the IOCTL requires exploiting a TOCTOU bug arguably caused by poor documentation of the SeLocateProcessImageName function. (3) Reimplementation of the driver’s security through obscurity IOCTL encryption scheme: SHA-256 KDF-derived XOR keystream & CRC16 Checksum. See full write-up, and Github for PoC. submitted by /u/p0xq [link] [comments]Technical Information Security Content & DiscussionRead More