Executive brief
EaseUS Partition Master is a popular disk management utility used to resize, clone, and manage hard drive partitions. A security flaw in its kernel driver allows a standard user to bypass Windows security protections and gain direct access to the computer's physical disks. This could allow an attacker to read or modify sensitive files belonging to other users or the system, potentially leading to a full takeover of the computer.
Technical details
A local privilege escalation vulnerability exists in EaseUS Partition Master (up to version 14.5) within the EUEDKEPM.sys kernel driver. The driver exposes a device path (\\.\EUEDKEPM\<disk>) that does not properly enforce Windows access control checks. A local attacker with standard user privileges can open this device to perform raw read and write operations directly against physical disks. This bypasses NTFS file permissions and OS-level disk protections, allowing for the disclosure or modification of protected system files and the potential for full local privilege escalation. The issue is resolved in versions newer than 14.5.
Affected products
- EaseUS Partition Master Up to 14.5
Timeline
- 2026-06-21: disclosed: Vulnerability disclosed and CVE-2026-12782 assigned.
- 2026-06-21: advisory: NVD and VulDB published details.
References
- https://vuldb.com/cve/CVE-2026-12782
- https://vuldb.com/submit/835612
- https://vuldb.com/vuln/372523
- https://vuldb.com/vuln/372523/cti
- https://winslow1984.com/books/cve-collection/page/easeus-partition-master-145-kernel-driver-euedkepmsys-local-privilege-escalation
- https://www.easeus.com/partition-manager/