Impact
A weakness exists in the pwdrvio.sys kernel driver used by MiniTool Partition Wizard versions up to 13.6. An unknown function in the driver does not enforce the necessary access controls, which allows a local attacker to break out of the limited user context and gain elevated privileges within the operating system. The vulnerability is classified as CWE‑266 and CWE‑284, and if successfully exploited the attacker could modify system configuration, install software, or otherwise compromise the integrity of the host. Publicly available exploits have been disclosed, indicating that the flaw is actionable in real-world environments.
Affected Systems
The affected product is MiniTool Partition Wizard for Windows. All installations of version 13.6 or earlier are vulnerable; upgrading to version 13.9 or later replaces the kernel driver and removes the flaw. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 4.8 places the vulnerability in the moderate severity range, but the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been widely abused. However, since the attack can only be launched from an already compromised local machine, the exploit scenario remains limited to users who can execute code on the target system. Attackers could use the public exploit to elevate privileges quickly, so the risk can change if a new vector emerges or the exploit becomes more convenient.
OpenCVE Enrichment