CVE-2026-79417 is an improper access-control vulnerability in the ArgusMonitor.sys driver in Argotronic eGbR ArgusMonitor 7.4.02 and earlier. A time-of-check to time-of-use condition in IRP_MJ_CREATE handling permits a local low-privileged user to bypass device-handle access restrictions and issue a crafted IOCTL request. The exposed IOCTL can disable the x86 MONITOR and MWAIT instructions used by Hyper-V and other kernel components, causing a HYPERVISOR_ERROR bugcheck.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains an MIT license, a README, and one C source file, exploit/exploit.c. It is a functional local proof of concept for CVE-2026-79417 affecting Argus Monitor <= 7.4.02 on Windows systems with AMD processors. The program accepts a path to an affected signed ArgusMonitor.exe binary. It renames its own executable to a .bak file, copies the supplied signed binary into its original location, and opens the Argus Monitor main and hdd device interfaces. This is intended to exploit a time-of-check/time-of-use weakness in the driver's SeLocateProcessImageName-based create-handler validation. The source implements the driver's request protocol: Modbus CRC-16 request checksums, a random 32-byte secret key, a fixed HMAC-SHA256-derived KDF context, SHA-256 keystream generation, and XOR encryption/decryption for IOCTL data. After establishing the secret with IOCTL 0x9C4024C4, it invokes the exposed read/write MSR IOCTLs. It reads AMD HWCR MSR 0xC0010015, sets bit 9 (MonMwaitDis), and writes the value back. The README and final status message explicitly characterize the outcome as local denial of service/system instability. No network communications, shell payload, persistence mechanism, or remote-control capability is present.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local denial-of-service vulnerability in the ArgusMonitor.sys driver shipped with Argotronic eGbR ArgusMonitor 7.4.02 and earlier. A low-privileged local user can exploit a time-of-check/time-of-use condition during IRP_MJ_CREATE to bypass device-handle access restrictions and issue crafted IOCTL 0x9C4024A8 requests.
A local denial-of-service vulnerability in Argus Monitor. An unprivileged local user can exploit a TOCTOU condition to reach an exposed driver IOCTL, disable x86 MONITOR/MWAIT instructions, and cause a HYPERVISOR_ERROR system bugcheck.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.