CVE-2026-12778 Details
Description
A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A local privilege escalation vulnerability has been identified in AOMEI Partition Assistant Standard versions through 10.10.1. The issue resides in the kernel driver 'ampa10.sys', which improperly manages access controls by exposing the '\\.\wowrt' device to standard local users. This vulnerability allows unprivileged users to perform raw disk read and write operations that bypass normal Windows access restrictions, potentially leading to unauthorized modifications of file system structures or other privileged data.
To address this vulnerability, the driver should be modified to create the exposed device with a restrictive security descriptor that limits access to administrators only. Additionally, the driver should set the 'FILE_DEVICE_SECURE_OPEN' flag for the device, reject user-mode callers for raw disk forwarding paths unless explicitly authorized, and implement per-request authorization checks for any operations that read or write raw disk sectors.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 21, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-12778 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/835607 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/372519 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/372519/cti | [email protected] | Content Wall |
| https://winslow1984.com/books/cve-collection/page/aomei-partition-assistant-10101-kernel-driver-ampa10sys-local-privilege-escalation | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AOMEI Partition Assistant | 10.10.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 21, 2026 | New CVE Received | [email protected] |
Volerion