CVE-2026-12784: Improper Access Controls in IM-Magic Partition Resizer
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
CVE-2026-12784 is an improper access control vulnerability in the kernel driver (MDA_NTDRV.sys) of IM-Magic Partition Resizer versions up to 7.9.0. The flaw allows a local attacker with limited privileges to manipulate the driver in a way that bypasses intended access restrictions. Although the vendor was notified early, no response or fix has been provided. Public exploit code is available, indicating potential for active exploitation. The CVSS 4.0 base score is 8.5, reflecting high impact on confidentiality, integrity, and availability with low attack complexity and no user interaction required.
Potential Impact
An attacker with local access can exploit this vulnerability to bypass access controls in the kernel driver, potentially leading to unauthorized actions affecting system confidentiality, integrity, and availability. The high CVSS score indicates significant risk if exploited. Public exploit code availability increases the likelihood of exploitation attempts. No vendor fix or mitigation has been confirmed, leaving affected systems exposed.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor, and the vendor has not responded to disclosure attempts. Users should restrict local access to trusted personnel only and consider disabling or uninstalling IM-Magic Partition Resizer until a fix is released. Monitor vendor channels for updates and apply any future patches promptly. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-12784: Improper Access Controls in IM-Magic Partition Resizer
Description
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 8.5high
Affected software
cpe:2.3:a:im-magic:partition_resizer:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12784 is an improper access control vulnerability in the kernel driver (MDA_NTDRV.sys) of IM-Magic Partition Resizer versions up to 7.9.0. The flaw allows a local attacker with limited privileges to manipulate the driver in a way that bypasses intended access restrictions. Although the vendor was notified early, no response or fix has been provided. Public exploit code is available, indicating potential for active exploitation. The CVSS 4.0 base score is 8.5, reflecting high impact on confidentiality, integrity, and availability with low attack complexity and no user interaction required.
Potential Impact
An attacker with local access can exploit this vulnerability to bypass access controls in the kernel driver, potentially leading to unauthorized actions affecting system confidentiality, integrity, and availability. The high CVSS score indicates significant risk if exploited. Public exploit code availability increases the likelihood of exploitation attempts. No vendor fix or mitigation has been confirmed, leaving affected systems exposed.
Mitigation Recommendations
No official patch or remediation is currently available from the vendor, and the vendor has not responded to disclosure attempts. Users should restrict local access to trusted personnel only and consider disabling or uninstalling IM-Magic Partition Resizer until a fix is released. Monitor vendor channels for updates and apply any future patches promptly. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-20T09:41:41.728Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a37914d9c760d8addaa3201
Added to database: 06/21/2026, 07:22:53 UTC
Last enriched: 06/28/2026, 21:50:39 UTC
Last updated: 08/04/2026, 15:46:50 UTC
Views: 200
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.