CVE-2026-12781: EaseUS Partition Master Kernel Driver Privilege Escalation
EaseUS Partition Master versions up to 14.5 contain a kernel driver vulnerability that allows authenticated local users to bypass security controls and gain elevated privileges. An attacker with legitimate access to a system running the affected software can exploit an improper access control flaw in the epmntdrv.sys driver to read, modify, or disrupt system functionality. The vendor has confirmed the issue only existed in older versions and has been resolved in current releases.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.8 HIGH · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-266, CWE-284
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-21 / 2026-06-22
NVD description (verbatim)
A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be used. You should upgrade the affected component. The vendor explains: "We have confirmed that this issue was present only in older versions of the product. Our product has since been updated, and the issue has been resolved in the latest version, so it no longer exists."
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12781 is a local privilege escalation vulnerability in EaseUS Partition Master affecting versions up to 14.5. The vulnerability resides in an unknown function within the epmntdrv.sys kernel driver component and stems from improper access control implementation (CWE-266, CWE-284). The flaw allows a local, unprivileged user to interact with the kernel driver in an unintended manner, resulting in confidentiality, integrity, and availability impacts. The CVSS 3.1 score of 7.8 (HIGH) reflects the requirement for local access but the significant scope of potential damage once exploited. Publicly available exploit code exists for this vulnerability.
Business impact
Compromise of systems running vulnerable EaseUS Partition Master versions could allow internal attackers or adversaries with initial system access to escalate privileges and gain full system control. This may lead to unauthorized access to sensitive data, system configuration changes, malware installation, or lateral movement within enterprise networks. Organizations relying on Partition Master for disk management should prioritize remediation to prevent insider threats and post-compromise escalation scenarios.
Affected systems
EaseUS Partition Master versions up to and including 14.5 are confirmed vulnerable. The vendor indicates the issue has been resolved in later versions. Organizations should verify their current Partition Master deployment versions against the vendor's advisory to identify affected systems. Affected systems require local user-level access to exploit, limiting but not eliminating risk in shared or multi-user environments.
Exploitability
The vulnerability has a relatively high exploitability bar requiring local system access and authentication, but public exploit code is available, lowering the technical barrier for attackers. This means threat actors with initial foothold on a target system—whether through phishing, supply chain compromise, or lateral movement—can readily weaponize this flaw to elevate privileges without significant additional development effort. The lack of user interaction required (UI:N) means exploitation can be automated and silent.
Remediation
Upgrade all instances of EaseUS Partition Master to a version after 14.5. The vendor has confirmed the issue is resolved in current releases. Organizations should validate the exact patched version through the vendor's official advisories before deploying. For systems that cannot be immediately updated, restrict kernel driver loading permissions to trusted administrators and limit local user account privileges where operationally feasible.
Patch guidance
Contact EaseUS directly or visit their official website to obtain the latest version of Partition Master, which resolves this vulnerability. Verify patch availability through the vendor's security advisory to confirm your target version addresses CVE-2026-12781. Deploy updates through your standard change management process, prioritizing systems in high-risk environments. Test updates in a non-production environment first to ensure compatibility with your disk management workflows.
Detection guidance
Monitor for unusual access attempts to kernel drivers, particularly epmntdrv.sys. Detection opportunities include: auditing privileged kernel driver load/unload operations, monitoring unusual process interactions with device drivers, and tracking failed access control checks on low-level disk management functions. Endpoint Detection and Response (EDR) tools configured to flag suspicious kernel-mode driver activity should detect exploitation attempts. Review system logs for unexpected calls to the affected driver component.
Why prioritize this
Despite not being tracked in the CISA Known Exploited Vulnerabilities catalog, the HIGH CVSS score (7.8) combined with publicly available exploits and the prevalence of Partition Master in enterprise disk management pipelines warrants urgent attention. This is an ideal post-compromise privilege escalation vector for attackers already present on systems, making it a key vector to block in lateral movement prevention strategies.
Risk score, explained
The CVSS 3.1 score of 7.8 (HIGH) reflects: Local Attack Vector (AV:L) requiring physical or logical system access, Low Attack Complexity (AC:L) with straightforward exploitation, Low Privilege Requirements (PR:L) needing only basic user-level access, No User Interaction (UI:N) enabling automated exploitation, and High impact across Confidentiality, Integrity, and Availability (C:H/I:H/A:H). The score appropriately weighs the severity of full system compromise achievable through this driver-level access path despite the local-access requirement.
Frequently asked questions
Do we need to update if we're running Partition Master in read-only mode?
No, read-only configurations do not eliminate the risk. An attacker could still exploit the vulnerability to gain unauthorized privileged access or information disclosure. All affected versions should be updated regardless of usage mode.
Is this vulnerability exploitable remotely over a network?
No. The attack vector is explicitly Local (AV:L), requiring the attacker to have interactive access to the target system. Remote exploitation is not possible, but any compromise that gives an attacker initial system access makes this vulnerability a high-value escalation path.
What should we do if we can't update immediately?
Implement compensating controls: restrict user permissions on systems running Partition Master, disable or restrict kernel driver loading privileges to administrators only, monitor for suspicious driver access attempts, and increase logging on systems that must remain on older versions. Develop an expedited update timeline as a priority.
Has this vulnerability been actively exploited in the wild?
The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog, indicating no widespread in-the-wild exploitation has been formally documented. However, the availability of public exploits means risk of opportunistic exploitation exists, and sophisticated threat actors may use it for targeted attacks without public disclosure.
This analysis is based on vendor statements and publicly disclosed information current as of the vulnerability's publication date. Patch availability and version numbers should be verified against official vendor advisories before deployment. The existence of public exploit code increases exploitation likelihood but does not guarantee active weaponization in your environment. This assessment does not constitute a guarantee of security and should be combined with your organization's risk assessment and testing protocols. Always consult the vendor's official security bulletin for definitive remediation guidance. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-12529HIGHSourceCodester CET Grading System Improper Access Control Vulnerability
- CVE-2026-12778HIGHAOMEI Partition Assistant Kernel Driver Privilege Escalation
- CVE-2026-12779HIGHAOMEI Dynamic Disk Manager Privilege Escalation in ddmdrv.sys
- CVE-2026-12780HIGHAOMEI Backupper Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-12782HIGHEaseUS Partition Master Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-12784HIGHIM-Magic Partition Resizer Kernel Driver Privilege Escalation
- CVE-2026-12786HIGHUltraISO Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-10152MEDIUMImproper Access Control in TaleLin lin-cms-spring-boot Book Endpoint