Executive brief
Portwell Engineering Toolkits, a software suite used in industrial and critical manufacturing environments, contains a vulnerability in its kernel-mode driver. A local user with basic access to the system can exploit this flaw to read or write to restricted memory areas. This could allow an attacker to take full control of the computer or crash the system, potentially disrupting critical infrastructure operations.
Technical details
An Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) exists in the Portwell Engineering Toolkits driver. The vulnerability is rooted in insufficient restrictions on low-level hardware access paths within the driver component. A local authenticated attacker can leverage these unsafe paths to perform arbitrary memory read and write operations. Successful exploitation allows for a complete bypass of security boundaries, enabling privilege escalation to SYSTEM level or causing a kernel-mode denial-of-service (BSOD). The issue is remediated in version 5.0.0 by hardening the driver and restricting access to these hardware paths.
Affected products
- Portwell Engineering Toolkits 4.8.2 and earlier
Timeline
- 2026-03-03: disclosed: Initial publication by CISA and NVD
- 2026-03-03: advisory: CISA ICSA-26-062-04 published
- 2026-06-18: patched: Portwell released version 5.0.0 to address the vulnerability