[Incident] WinRing0 Known Security Vulnerability
Recently the driver for OpenRGB was changed to use WinRing0 (in !1036 (merged)). Unfortunately, that version of WinRing0 (and potentially all versions) contain a security vulnerability, as noted here: https://voidsec.com/crucial-mod-utility-lpe-cve-2021-41285/ (CVE-2021-41285).
I verified the SHA-1 hash of WinRing0x64.sys used in this project match the SHA-1 of the vulnerable version in the linked CVE. So OpenRGB now has the same vulnerability.
I can't say for sure that the previous driver doesn't have vulnerabilities, but this one is known to. It might be wise to revert to the previous driver until a fixed version of WinRing0 can be made (if that is even possible). Or at least advise people of the danger of running this driver so they can make an informed decision.