Junglewise Threat Intelligence

CVE-2026-12786: Ezbsystems UltraISO Premium Edition privilege escalation in bootpt64.sys

CVE-2026-12786 · Severity: high · CVSS 7.8 · Published 2026-06-21

Executive brief

A security vulnerability exists in UltraISO Premium Edition, a tool used for creating and managing disk image files. A flaw in one of its core system components allows a standard user on a computer to bypass Windows security restrictions and gain direct access to the hard drive. This could allow an attacker to read sensitive files they shouldn't see or modify system data to take full control of the machine.

Technical details

A local privilege escalation vulnerability exists in the bootpt64.sys kernel driver of Ezbsystems UltraISO Premium Edition (up to version 9.76). The driver exposes the '\\.\BootPart' device object with improper access controls, granting 'Builtin Users' the ability to interact with it. By sending IOCTL 0x7F300, a low-privileged attacker can mount a physical disk range and subsequently use standard ReadFile/WriteFile operations to perform raw disk I/O. This bypasses Windows NTFS permissions and raw disk access checks, allowing an attacker to read protected files or achieve full system compromise by tampering with sensitive filesystem metadata or boot structures. As of the advisory date, the vendor has not responded to disclosure attempts.

Affected products

  • Ezbsystems UltraISO Premium Edition Up to 9.76

Timeline

  • 2026-06-21: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-06-21: advisory: CVE-2026-12786 published.

References