AI description
CVE-2026-12784 identifies a weakness within IM-Magic Partition Resizer software, specifically affecting versions up to 7.9.0. The vulnerability is located in an unspecified function within the `MDA_NTDRV.sys` kernel driver library, which is a component of the software. This flaw is characterized as an improper access control issue. Exploitation of CVE-2026-12784 requires local access to the affected system. The nature of this weakness suggests a failure in privilege separation or access validation mechanisms at the kernel level. A public exploit for this vulnerability has been made available.
- Description
- A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
- Source
- cna@vuldb.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 7.1
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Secondary
- Base score
- 6.8
- Impact score
- 10
- Exploitability score
- 3.1
- Vector string
- AV:L/AC:L/Au:S/C:C/I:C/A:C
- cna@vuldb.com
- CWE-266
- Hype score
- Not currently trending
CVE-2026-12784 Local Privilege Escalation in IM-Magic Partition Resizer Up to 7.9.0 https://t.co/lNB2duoKGK
@VulmonFeeds
21 Jun 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Utilized LLM and discovered kernel drivers' vulnerabilities, 8 of them are already credited, all of them are LPE vulnerabilities: CVE-2026-12217, CVE-2026-12778, CVE-2026-12779, CVE-2026-12780, CVE-2026-12781, CVE-2026-12782, CVE-2026-12784, CVE-2026-12786
@senzee1984
20 Jun 2026
5137 Impressions
2 Retweets
47 Likes
25 Bookmarks
1 Reply
0 Quotes