---
id: CVE-2026-79417
title: >-
  Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor
  7.4.02 and earlier allows local, low-privileged users to bypass device handle
  access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted
  IOCT…
summary: >-
  Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor
  7.4.02 and earlier allows local, low-privileged users to bypass device handle
  access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted
  IOCT…
severity: none
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T20:17:26.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79417'
references:
  - url: >-
      https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
  - exploit-available
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/connorjaydunn/CVE-2026-79417'
  checkedAt: '2026-09-29T20:46:41.298Z'
exploitAvailable: true
ingestedAt: '2026-09-29T20:46:06.449Z'
---

## Overview

Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
