CVE-2026-12784: IM-Magic Partition Resizer Kernel Driver Privilege Escalation
IM-Magic Partition Resizer versions up to 7.9.0 contain a security flaw in its kernel driver (MDA_NTDRV.sys) that fails to properly enforce access controls. An attacker with local system access could exploit this weakness to gain elevated privileges or interfere with system integrity. Public exploit code now exists, elevating the practical risk. The vendor has not responded to early disclosure attempts, leaving affected users without an official patch.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.8 HIGH · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-266, CWE-284
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-21 / 2026-06-22
NVD description (verbatim)
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
5 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from improper access control mechanisms in the MDA_NTDRV.sys kernel driver component. Classified under CWE-266 (Incorrect Privilege Assignment) and CWE-284 (Improper Access Control), it allows a local, low-privileged user to manipulate driver functionality without proper authorization. The attack vector is local with low complexity and no user interaction required. An attacker leveraging this flaw can achieve read, write, and execute access outside their intended permission scope, potentially leading to full system compromise.
Business impact
Organizations relying on IM-Magic Partition Resizer face risk of privilege escalation and data integrity compromise. A local attacker—such as a disgruntled employee or compromised account holder—could escalate to administrative access, modify disk partitions, encrypt or destroy data, or install persistent malware. The combination of public exploits and vendor non-responsiveness means mitigation cannot wait for an official patch, forcing immediate operational decisions.
Affected systems
IM-Magic Partition Resizer through version 7.9.0 is affected. The flaw resides in the kernel driver component, making it a system-level risk affecting all instances where the software is installed with driver privileges enabled. Any Windows system running a vulnerable version is at risk if a local user account exists that could be compromised or leveraged by an insider.
Exploitability
This vulnerability is exploitable with local access and low privilege; no special conditions or user interaction are required. Critically, public exploit code is now available, reducing the barrier to weaponization. Attackers need only system access—via a low-privilege account, remote shell, or persistence mechanism from a prior compromise—to trigger the flaw. The lack of complexity and availability of working exploits position this as a practical, high-impact attack vector.
Remediation
Immediate steps include identifying and inventorying all systems running IM-Magic Partition Resizer up to version 7.9.0. Evaluate whether the partition resizing functionality is necessary; if not, uninstall the software entirely. If continued use is required, verify with the vendor whether version 7.10.0 or later addresses this flaw, or contact IM-Magic support directly for an emergency patch. Restrict local system access through privilege management and monitoring. Consider disabling or sandboxing the driver where operationally feasible.
Patch guidance
Check the vendor's official advisory and product updates page for patched versions beyond 7.9.0. Verify the patch version against IM-Magic's security bulletins before deployment. If no patch is forthcoming after reasonable time, plan for migration to an alternative disk management solution. Test any patch in a non-production environment first, as kernel driver updates can impact system stability. Monitor vendor communications for updates, given the current lack of response.
Detection guidance
Monitor for unexpected kernel driver load/unload events involving MDA_NTDRV.sys. Use endpoint detection and response (EDR) tools to flag privilege escalation attempts originating from processes interacting with the driver. Enable Windows Audit Policy logging for privilege use and object access. Check process creation logs for unusual child processes spawned by applications using the driver. Forensic analysis should focus on driver parameter tampering and unauthorized system calls that bypass normal access control checks.
Why prioritize this
This vulnerability merits urgent prioritization due to: (1) CVSS 7.8 (HIGH) severity with full confidentiality, integrity, and availability impact; (2) public availability of working exploits; (3) local privilege escalation potential on affected systems; (4) vendor non-responsiveness limiting remediation options; and (5) kernel-level access implications. Any system running this software in an environment with multiple local user accounts or where lateral movement from compromised accounts is possible should be remediated within days, not weeks.
Risk score, explained
The CVSS 3.1 score of 7.8 reflects high severity: local attack vector, low complexity, low privilege requirements, no user interaction needed, and severe impact across confidentiality, integrity, and availability. The score does not fully capture the added risk from publicly available exploits and vendor non-responsiveness, both of which increase real-world exploitability and reduce effective time-to-remediation. Organizations should treat this as a critical asset if partition management is central to their operations.
Frequently asked questions
Do I need IM-Magic Partition Resizer for Windows to work?
Partition Resizer is a disk management utility, not a core Windows component. Many organizations use built-in Windows tools or third-party alternatives. Evaluate whether you actively use resizing features; if not, uninstall to eliminate the risk. If you do depend on it, begin planning a transition to a verified secure alternative.
Can this vulnerability be exploited remotely?
No. The attack vector is local-only, requiring an attacker to have an account or shell access on the target system. However, this is still critical in environments where local user accounts exist, where privilege escalation is a concern, or where an attacker has already gained initial access via another vulnerability.
What should I do if I cannot update immediately?
Prioritize uninstalling the software if not operationally essential. If you must keep it, restrict local system access via privilege management and strong authentication, isolate the affected system from sensitive network resources, and increase monitoring for suspicious driver activity. Verify any patch version before applying it.
Is the vendor planning to release a patch?
The vendor has not responded to early disclosure attempts. Check their official website and security advisory channels regularly for updates. If no patch emerges within a reasonable timeframe (typically 30–90 days from disclosure), plan for migration to an alternative solution rather than waiting indefinitely.
This analysis is based on publicly available vulnerability data as of the publication date. Vendor information, patch availability, and product status may change. Organizations should verify patch versions and compatibility against official vendor advisories before deployment. This assessment does not constitute professional security advice; consult your security team for environment-specific guidance. No exploit code, proof-of-concept details, or weaponization instructions are provided herein. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-12529HIGHSourceCodester CET Grading System Improper Access Control Vulnerability
- CVE-2026-12778HIGHAOMEI Partition Assistant Kernel Driver Privilege Escalation
- CVE-2026-12779HIGHAOMEI Dynamic Disk Manager Privilege Escalation in ddmdrv.sys
- CVE-2026-12780HIGHAOMEI Backupper Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-12781HIGHEaseUS Partition Master Kernel Driver Privilege Escalation
- CVE-2026-12782HIGHEaseUS Partition Master Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-12786HIGHUltraISO Kernel Driver Privilege Escalation Vulnerability
- CVE-2026-10152MEDIUMImproper Access Control in TaleLin lin-cms-spring-boot Book Endpoint