Junglewise Threat Intelligence

CVE-2026-12781: EaseUS Partition Master privilege escalation in epmntdrv.sys kernel driver

CVE-2026-12781 · Severity: high · CVSS 7.8 · Published 2026-06-21

Executive brief

EaseUS Partition Master is a disk management utility used to resize, clone, and manage hard drive partitions. A security flaw in its kernel driver allows a standard computer user to bypass Windows security protections and gain direct access to the physical hard drive. This could allow an attacker to read or modify sensitive system files, potentially leading to a full takeover of the computer.

Technical details

A vulnerability in the epmntdrv.sys kernel driver of EaseUS Partition Master (up to version 14.5) stems from improper access controls on a legacy device path (\\.\EPMNTDRV\<disk>). The driver exposes a user-openable device that forwards raw read and write I/O Request Packets (IRPs) to the lower storage stack without enforcing standard Windows access checks. A local attacker with standard user privileges can exploit this to perform raw disk operations, bypassing NTFS file permissions to read or overwrite protected system data. This primitive can be used to achieve local privilege escalation (LPE). The vendor has addressed this in later versions of the product.

Affected products

  • EaseUS Partition Master Up to 14.5

Timeline

  • 2026-06-21: advisory: NVD publication date
  • 2026-06-21: disclosed: Initial disclosure via VulDB

References

Related threats