CVE-2026-12784 Details
Description
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A local privilege escalation vulnerability has been identified in IM-Magic Partition Resizer Free Portable versions through 7.9.0. The issue resides in the kernel driver MDA_NTDRV.sys, which improperly manages access controls. This vulnerability allows standard local users to bypass Windows file access control lists (ACLs) and manipulate protected file data at the raw disk level. The exploitation involves reading and writing to files that are restricted to administrative access, using the vulnerable driver to circumvent normal security measures.
Users are advised not to expose raw disk forwarding devices to unprivileged users. Instead, create device objects that only allow access to administrators or trusted services, and validate caller identities and access rights before forwarding raw disk operations. Additionally, known vulnerable driver hashes should be added to blocklists until a fix is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 21, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-12784 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/835613 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/372524 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/372524/cti | [email protected] | Content Wall |
| https://winslow1984.com/books/cve-collection/page/im-magic-partition-resizer-790-kernel-driver-mda-ntdrvsys-local-privilege-escalation | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| IM-Magic Partition Resizer Free Portable | 7.9.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 21, 2026 | New CVE Received | [email protected] |
Volerion