Back to overview

CVE-2026-12779

HIGH
7.8
CVSS 3.1
Description
A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metadata

CVE ID
CVE-2026-12779
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-20 09:36 UTC
Published
2026-06-21 05:15 UTC
Last updated
2026-06-21 05:15 UTC
Primary CWE
CWE-284
Improper Access Controls
Vendor / Product
AOMEI / Dynamic Disk Manager
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Affected products (1)
VendorProductPlatformVersions
AOMEI Dynamic Disk Manager 10.10.0, 10.10.1
Weakness (CWE)
CWESourceDescription
CWE-266 cna Incorrect Privilege Assignment
CWE-284 cna Improper Access Controls
CVSS scores (4)
ScoreSeverityVersionSourceVector
8.5 HIGH 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
7.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
7.8 HIGH 3.0 cna CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
6.8 N/D 2.0 cna AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR
References (5)
Back to overview