Description
A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. It is suggested to upgrade the affected component.
Published: 2026-07-12
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A known vulnerability exists in QILING Disk Master 6.0.0.0 within its kernel driver component diskbckp.sys. An unknown function in that driver permits local users to bypass normal access control, allowing the execution of code with kernel privileges. This flaw is a proper access-control weakness classified as CWE-266 and CWE-284. The main consequence is that a privileged local attacker can obtain full system control, potentially undermining the integrity and confidentiality of all data stored or processed by the affected machine.

Affected Systems

QILING Disk Master version 6.0.0.0, a disk backup and recovery application distributed with a kernel driver component. Any system running this exact version is affected; newer releases are not known to contain vulnerability resides in the kernel driver diskbckp.sys of QILING Disk Master 6.0.0.0, where improper access controls allow a local attacker to gain elevated privileges on the system. The weakness is classified under CWE-266 (Improper Privilege Management) and CWE-284 (Improper Access Control). It is inferred that an attacker who achieves kernel-level privileges can execute arbitrary code with full system control.

Risk and Exploitability

The CVSS score is 4.8, indicating moderate severity. EPSS is below 1%, and the vulnerability is not listed in the KEV catalog, implying low public exploitation probability. However, because the vector is local only, an attacker with local access can leverage the weakened driver to execute code with elevated kernel privileges, potentially leading to full system compromise. Limiting local user privileges and auditing driver usage will reduce the risk.

Generated by OpenCVE AI on August 1, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor-supplied upgrade for QILING Disk Master that addresses diskbckp.sys access control issues.
  • If no update is available, enforce least-privilege permissions for local users and disable the diskbckp.sys kernel driver when not in use.
  • Continuously monitor system logs for unauthorized loading of diskbckp.sys and for attempts to exploit access-control weaknesses.

Generated by OpenCVE AI on August 1, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. It is suggested to upgrade the affected component.
Title QILING Disk Master Kernel Driver diskbckp.sys access control
First Time appeared Qiling
Qiling disk Master
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:qiling:disk_master:*:*:*:*:*:*:*:*
Vendors & Products Qiling
Qiling disk Master
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Qiling Disk Master
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T16:08:06.824Z

Reserved: 2026-07-11T09:44:33.072Z

Link: CVE-2026-15476

cve-icon Vulnrichment

Updated: 2026-07-13T16:08:00.877Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control