CVE-2022-29320

HIGH

MiniTool Partition Wizard v12.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-29320. PoCs published by Saud Alenazi.

AI-analyzed exploit summary The provided content demonstrates an unquoted service path vulnerability in MiniTool Partition Wizard 12.0, where the service path contains spaces and lacks quotes, potentially allowing local privilege escalation via executable spoofing. The output includes service configuration and file permissions, confirming the vulnerability's presence.

Description

MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

Exploits (1)

exploitdb WRITEUP
by Saud Alenazi · textlocalwindows
https://www.exploit-db.com/exploits/50859

The provided content demonstrates an unquoted service path vulnerability in MiniTool Partition Wizard 12.0, where the service path contains spaces and lacks quotes, potentially allowing local privilege escalation via executable spoofing. The output includes service configuration and file permissions, confirming the vulnerability's presence.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: MiniTool Partition Wizard 12.0
Auth required
Prerequisites: Local access to the system · Ability to create executables in the vulnerable path
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50859

Scores

CVSS v3 7.8
EPSS 0.0042
EPSS Percentile 33.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
minitool/partition_wizard 12.0
Published May 20, 2022
Tracked Since Feb 18, 2026