Description
A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. Upgrading to version 13.9 is sufficient to fix this issue. The affected component should be upgraded. The vendor was contacted early about this disclosure.
Published: 2026-07-12
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A weakness exists in the pwdrvio.sys kernel driver used by MiniTool Partition Wizard versions up to 13.6. An unknown function in the driver does not enforce the necessary access controls, which allows a local attacker to break out of the limited user context and gain elevated privileges within the operating system. The vulnerability is classified as CWE‑266 and CWE‑284, and if successfully exploited the attacker could modify system configuration, install software, or otherwise compromise the integrity of the host. Publicly available exploits have been disclosed, indicating that the flaw is actionable in real-world environments.

Affected Systems

The affected product is MiniTool Partition Wizard for Windows. All installations of version 13.6 or earlier are vulnerable; upgrading to version 13.9 or later replaces the kernel driver and removes the flaw. No other versions are listed as affected.

Risk and Exploitability

The CVSS score of 4.8 places the vulnerability in the moderate severity range, but the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been widely abused. However, since the attack can only be launched from an already compromised local machine, the exploit scenario remains limited to users who can execute code on the target system. Attackers could use the public exploit to elevate privileges quickly, so the risk can change if a new vector emerges or the exploit becomes more convenient.

Generated by OpenCVE AI on August 1, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update MiniTool Partition Wizard to version 13.9 or later to replace the vulnerable pwdrvio.sys driver.
  • Restart the computer after updating to ensure the new driver is loaded and the old driver is no longer active.
  • Check the vendor’s website regularly for security updates and patches until the issue is addressed.

Generated by OpenCVE AI on August 1, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. Upgrading to version 13.9 is sufficient to fix this issue. The affected component should be upgraded. The vendor was contacted early about this disclosure.
Title MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control
First Time appeared Minitool
Minitool partition Wizard
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:minitool:partition_wizard:*:*:*:*:*:*:*:*
Vendors & Products Minitool
Minitool partition Wizard
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Minitool Partition Wizard
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T14:38:31.090Z

Reserved: 2026-07-11T09:40:55.072Z

Link: CVE-2026-15475

cve-icon Vulnrichment

Updated: 2026-07-13T14:38:25.465Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control