CVE-2026-12782 Details
Description
A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The affected component should be upgraded. The vendor explains: "We have confirmed that this issue was present only in older versions of the product. Our product has since been updated, and the issue has been resolved in the latest version, so it no longer exists."
A local privilege escalation vulnerability has been identified in EaseUS Partition Master versions prior to 14.5. The issue resides in the kernel driver EUEDKEPM.sys, which improperly manages access controls, allowing standard users to execute raw disk read and write operations on physical disks. This vulnerability exploits the driver's lack of proper access checks, enabling unauthorized modification of protected files and potentially leading to elevated privileges.
Users are advised to update to the latest version of EaseUS Partition Master, where this vulnerability has been addressed. Additionally, the driver should be modified to prevent raw disk devices from being exposed to unprivileged users, implement secure device creation practices, and require explicit authorization for raw disk operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 21, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-12782 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/835612 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/372523 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/372523/cti | [email protected] | Content Wall |
| https://winslow1984.com/books/cve-collection/page/easeus-partition-master-145-kernel-driver-euedkepmsys-local-privilege-escalation | [email protected] | ExploitTechnical Description |
| https://www.easeus.com/partition-manager/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| EaseUS Partition Master | <= 14.5 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 21, 2026 | New CVE Received | [email protected] |
Volerion