Junglewise Threat Intelligence

CVE-2026-3437: Portwell Engineering Toolkits memory buffer vulnerability in driver

CVE-2026-3437 · Severity: high · CVSS 8.8 · Published 2026-03-03

Executive brief

Portwell Engineering Toolkits, a software suite used in industrial and critical manufacturing environments, contains a vulnerability in its kernel-mode driver. A local user with basic access to the system can exploit this flaw to read or write to restricted memory areas. This could allow an attacker to take full control of the computer or crash the system, potentially disrupting critical infrastructure operations.

Technical details

An Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) exists in the Portwell Engineering Toolkits driver. The vulnerability is rooted in insufficient restrictions on low-level hardware access paths within the driver component. A local authenticated attacker can leverage these unsafe paths to perform arbitrary memory read and write operations. Successful exploitation allows for a complete bypass of security boundaries, enabling privilege escalation to SYSTEM level or causing a kernel-mode denial-of-service (BSOD). The issue is remediated in version 5.0.0 by hardening the driver and restricting access to these hardware paths.

Affected products

  • Portwell Engineering Toolkits 4.8.2 and earlier

Timeline

  • 2026-03-03: disclosed: Initial publication by CISA and NVD
  • 2026-03-03: advisory: CISA ICSA-26-062-04 published
  • 2026-06-18: patched: Portwell released version 5.0.0 to address the vulnerability

References