---
id: CVE-2026-97732
title: >-
  IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that
  authenticates client executables by checking for expected publisher and
  root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and
  "DigiCert Trusted Root…
summary: >-
  IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that
  authenticates client executables by checking for expected publisher and
  root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and
  "DigiCert Trusted Root…
severity: medium
cvss: 5.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-347
vendor: IRONMACE
product: Ironshield
affected:
  - Ironshield 1.0.0.167
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T14:17:26.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97732'
references:
  - url: 'https://github.com/hseoa/ironshield-analysis'
    label: cve@mitre.org
  - url: 'https://store.steampowered.com/eula/2016590_eula_0'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00056
epssPercentile: 0.00003
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T13:42:40.635415Z'
ingestedAt: '2026-09-25T03:58:52.656Z'
---

## Overview

IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and "DigiCert Trusted Root G4") instead of parsing and validating the PKCS signature data. As a result, a local unprivileged attacker may bypass this via crafted certificate data and obtain access to privileged IOCTL functionality.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
