CVE-2026-15475
MiniTool Partition Wizard vulnerability analysis and mitigation

Overview

CVE-2026-15475 is an improper access control vulnerability affecting MiniTool Partition Wizard versions 13.0 through 13.6. The flaw resides in an unknown function within the signed kernel driver library pwdrvio.sys, allowing a local attacker with low privileges to exploit incorrect privilege assignment. It was disclosed on July 12, 2026, with the vendor contacted prior to public disclosure. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 1.9 (Low), with a proof-of-concept exploit publicly available (GitHub Advisory, VulDB).

Technical details

The vulnerability is classified under CWE-266 (Incorrect Privilege Assignment) and CWE-284 (Improper Access Control), rooted in the pwdrvio.sys signed kernel driver component shipped with MiniTool Partition Wizard. Because the driver is signed and loaded at the kernel level, improper access controls on its exposed interfaces may allow a low-privileged local user to interact with kernel-mode functionality in unintended ways. The attack vector is strictly local, requires low privileges, no user interaction, and low attack complexity. A public proof-of-concept has been published documenting the local privilege escalation technique (GitHub Advisory, winslow1984 PoC).

Impact

Successful exploitation results in limited but tangible impacts across confidentiality, integrity, and availability of the vulnerable system, each rated as low in scope. A local attacker could leverage the misconfigured kernel driver to read sensitive information, make unauthorized modifications to system data, or partially disrupt system availability. The scope is confined to the local machine with no subsequent system impact, limiting lateral movement potential, though kernel-level driver abuse could theoretically be chained with other techniques for privilege escalation (GitHub Advisory, VulDB).

Exploitability

A proof-of-concept exploit has been publicly released and is referenced in the advisory, making this vulnerability accessible to a broader range of attackers (GitHub Advisory). The EPSS score is approximately 0.105%, indicating a low near-term probability of widespread exploitation. The NVD SSVC assessment classifies exploitation as "poc" and notes it is not automatable. There is no current evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (VulDB).

Exploitation steps

  1. Reconnaissance: Identify target systems running MiniTool Partition Wizard versions 13.0–13.6 on Windows, where the vulnerable pwdrvio.sys kernel driver is installed and loaded.
  2. Verify driver presence: Confirm the signed kernel driver pwdrvio.sys is loaded using tools such as sc query, driverquery, or WinObj from Sysinternals.
  3. Interact with driver interface: Using a low-privileged user account, send crafted IOCTL (I/O Control Code) requests to the pwdrvio.sys driver via its exposed device interface, exploiting the improper access control that fails to restrict privileged operations to authorized callers.
  4. Abuse kernel-level access: Leverage the driver's misconfigured privilege handling to perform actions beyond the attacker's normal privilege level, such as reading protected memory, modifying system data, or executing code in a higher-privilege context.
  5. Achieve objective: Use the gained access to escalate privileges, disable security controls, or establish persistence on the compromised host (winslow1984 PoC, VulDB).

Indicators of compromise

  • File System: Presence of pwdrvio.sys in the MiniTool Partition Wizard installation directory on systems running versions 13.0–13.6; unexpected files or scripts dropped by low-privileged processes in system directories.
  • Logs: Windows Security Event Log entries showing privilege use or object access anomalies by non-administrative accounts; kernel driver load events (Event ID 7045) for pwdrvio.sys.
  • Process: Unusual processes spawned with elevated privileges from a low-privileged user session; unexpected IOCTL calls to the pwdrvio.sys device object observable via kernel debugging or EDR telemetry.
  • Registry: Unexpected modifications to service registry keys associated with pwdrvio.sys under HKLM\SYSTEM\CurrentControlSet\Services\.

Mitigation and workarounds

MiniTool has released version 13.9 of Partition Wizard, which resolves the improper access control issue in pwdrvio.sys. Users running versions 13.0 through 13.6 should upgrade to version 13.9 immediately. No configuration-based workaround has been published; upgrading is the only confirmed remediation. As an interim measure, organizations may consider restricting local user access to systems where MiniTool Partition Wizard is installed or monitoring for anomalous driver interactions (GitHub Advisory, MiniTool Upgrade History).

Community reactions

The vulnerability was assigned and disclosed by VulDB, which coordinated with the vendor prior to public disclosure. The GitHub Advisory Database published the advisory on July 12, 2026, classifying it as low severity. Social media activity has been limited, with automated CVE notification accounts on Bluesky and Nitter referencing the disclosure. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability aggregator postings (GitHub Advisory, VulDB).

Additional resources


SourceThis report was generated using AI

Related MiniTool Partition Wizard vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-38352HIGH8.1
  • MiniTool Partition Wizard logoMiniTool Partition Wizard
  • cpe:2.3:a:minitool:partition_wizard
NoNoSep 19, 2023
CVE-2023-38351HIGH8.1
  • MiniTool Partition Wizard logoMiniTool Partition Wizard
  • cpe:2.3:a:minitool:partition_wizard
NoNoSep 19, 2023
CVE-2022-29320HIGH7.8
  • MiniTool Partition Wizard logoMiniTool Partition Wizard
  • cpe:2.3:a:minitool:partition_wizard
NoYesMay 20, 2022
CVE-2026-15475LOW1.9
  • MiniTool Partition Wizard logoMiniTool Partition Wizard
  • cpe:2.3:a:minitool:partition_wizard
NoNoJul 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management