CVE-2026-12778 AOMEI Partition Assistant Kernel Driver Privilege Escalation
A privilege escalation flaw exists in AOMEI Partition Assistant version 10.10.1 and earlier, affecting the ampa10.sys kernel driver. An authenticated local attacker can exploit improper access controls in the driver to gain elevated system privileges, potentially compromising the entire system. The vulnerability has been publicly disclosed, and exploit code may be in circulation. The vendor has not responded to early disclosure attempts.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.8 HIGH · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-266, CWE-284
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-21 / 2026-06-22
NVD description (verbatim)
A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12778 involves improper access control mechanisms in the ampa10.sys kernel driver component of AOMEI Partition Assistant. The vulnerability stems from inadequate privilege checks (CWE-266) and insufficient access control enforcement (CWE-284) within the driver's interface. An unprivileged local user can leverage this flaw to escalate privileges without user interaction, achieving read, write, and execute capabilities at the system level. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects the local-only attack surface, low complexity exploitation, and high impact across confidentiality, integrity, and availability.
Business impact
Organizations relying on AOMEI Partition Assistant for disk management face significant risk. A compromised system could enable attackers to manipulate partitions, destroy data, install persistent malware, or pivot to other network resources. The lack of vendor responsiveness means no coordinated patches may be forthcoming, leaving affected deployments vulnerable indefinitely unless mitigation strategies are deployed. This is particularly concerning in environments where the tool is used administratively across multiple systems.
Affected systems
AOMEI Partition Assistant version 10.10.1 and all prior versions are affected. The vulnerability is triggered through the ampa10.sys kernel driver, which is installed as part of the standard application package. Any Windows system running a vulnerable version with local user access is at risk. Organizations should identify all machines with Partition Assistant deployed and verify their current version against 10.10.1.
Exploitability
Exploitation requires local system access and valid user credentials—a low barrier for internal threats, contractors, or compromised low-privilege accounts. The attack is trivial to execute (low complexity) once an attacker has initial foothold, and does not require social engineering. Public disclosure and possible exploit availability mean this vulnerability is likely to be targeted opportunistically. The lack of authentication bypass makes lateral movement necessary but elevates the risk for any local user session.
Remediation
Immediate action should focus on inventory and containment. Users should verify whether their version exceeds 10.10.1 by checking application version information. If a vendor patch becomes available, prioritize deployment in test environments first. Until a fix is released, consider restricting the application to trusted administrative accounts only, limiting local user privileges on systems running Partition Assistant, or temporarily removing the application from non-critical systems. Monitor vendor communications for any future guidance or patches.
Patch guidance
Check the AOMEI website and your product license portal for available updates beyond version 10.10.1. As of the vulnerability publication date, verify against the vendor advisory whether a patch has been released. If no patch is available and the application is business-critical, evaluate alternative disk management tools or implement compensating controls such as driver signature enforcement and application whitelisting. Document your patching decision and review quarterly for vendor updates.
Detection guidance
Monitor for suspicious kernel driver activity, privilege escalation attempts involving ampa10.sys, and unexpected system modifications initiated by unprivileged user processes. Endpoint detection and response (EDR) tools should flag attempts to communicate with or load the vulnerable driver with elevated intentions. Process monitoring may reveal abuse through disk partition manipulation utilities. Check for any suspicious use of Windows APIs related to privilege escalation in conjunction with Partition Assistant execution.
Why prioritize this
This vulnerability merits immediate prioritization due to its HIGH CVSS score (7.8), public exploit disclosure, and the vendor's non-responsiveness to early disclosure. The local privilege escalation vector impacts confidentiality, integrity, and availability equally, and the straightforward attack complexity means it can be exploited quickly once an attacker gains initial local access. In mixed-privilege environments, this becomes a rapid escalation path to system compromise.
Risk score, explained
The CVSS 3.1 score of 7.8 (HIGH) reflects: (1) local-only attack vector, limiting exposure to systems where users already have access; (2) low attack complexity, requiring no special conditions; (3) low privilege requirement, exploitable by standard users; (4) no user interaction needed; (5) high impact across all three security pillars (confidentiality, integrity, availability). The score would be critical if the attack vector were network-based, but remains high due to the complete system compromise potential within local attack scope.
Frequently asked questions
Do I need AOMEI Partition Assistant to be actively running for this vulnerability to be exploitable?
The vulnerability exists in the ampa10.sys kernel driver, which loads when the application is installed. Depending on the driver configuration, active exploitation may occur without the GUI running. Verify with your system whether the driver loads at boot or on-demand. To be safe, assume any system with the vulnerable version installed and the driver loaded is at risk.
The vendor hasn't responded to disclosure—what should I do while waiting for a patch?
Implement defense-in-depth: restrict local user privileges on affected systems, monitor for suspicious privilege escalation activity, consider application allowlisting, and ensure driver signature enforcement is enabled. Review whether this application is truly necessary on all systems where it's installed, and consider alternative tools for critical disk management tasks. Document your risk acceptance if you cannot remove the application.
How does this vulnerability differ from typical local privilege escalation flaws?
The key distinction is the kernel driver component and vendor non-responsiveness. Kernel driver flaws are often harder to patch at scale because they require driver signing, reboot, and careful testing. Combined with no vendor support, this creates a longer-term exposure window compared to standard application vulnerabilities.
Could this vulnerability be exploited over the network indirectly?
The attack vector is strictly local. However, if an attacker gains initial network access through another vulnerability and obtains local execution (e.g., via RDP, lateral movement), they could then use this flaw to escalate to SYSTEM privileges. This makes it a valuable second-stage exploit in multi-step attack chains.
This analysis is provided for informational purposes to support security decision-making. It is based on publicly disclosed vulnerability information as of the publication date. Organizations should verify all technical details against official vendor advisories and CVE records before making remediation decisions. Patch availability, version numbers, and vendor responsiveness may change; always confirm current status with AOMEI before deployment. This is not a substitute for professional security assessment or vendor guidance. Use this information to inform risk prioritization, not as definitive technical or legal advice. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-12529HIGHSourceCodester CET Grading System Improper Access Control Vulnerability
- CVE-2026-12779HIGHAOMEI Dynamic Disk Manager Privilege Escalation in ddmdrv.sys
- CVE-2026-12780HIGHAOMEI Backupper Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-12781HIGHEaseUS Partition Master Kernel Driver Privilege Escalation
- CVE-2026-12782HIGHEaseUS Partition Master Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-12784HIGHIM-Magic Partition Resizer Kernel Driver Privilege Escalation
- CVE-2026-12786HIGHUltraISO Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-10152MEDIUMImproper Access Control in TaleLin lin-cms-spring-boot Book Endpoint