Junglewise Threat Intelligence

CVE-2026-12784: IM-Magic Partition Resizer privilege escalation in MDA_NTDRV.sys

CVE-2026-12784 · Severity: high · CVSS 7.8 · Published 2026-06-21

Executive brief

IM-Magic Partition Resizer is a utility used to manage and resize hard drive partitions. A security flaw in its kernel driver allows a standard computer user to bypass Windows security restrictions and directly read or write data to the physical hard disk. This could allow an attacker to steal sensitive files, modify system settings, or gain full administrative control over the computer.

Technical details

A vulnerability exists in the MDA_NTDRV.sys kernel driver of IM-Magic Partition Resizer (up to version 7.9.0) due to improper access control on the device object \\.\MDA_NTDRV\<disk>. The driver exposes raw disk forwarding functionality to unprivileged local users, allowing them to perform direct read and write operations on physical disks. By bypassing standard Windows File System ACLs, a local attacker with medium integrity can read protected files or overwrite critical system components (such as service binaries or registry hives) to achieve local privilege escalation (LPE). Public exploit code has been released, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • IM-Magic Partition Resizer Up to 7.9.0

Timeline

  • 2026-06-21: disclosed: Vulnerability disclosed via VulDB and NVD
  • 2026-06-21: advisory

References