CVE-2026-3437

HIGH

Portwell Engineering Toolkits 4.8.2 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-3437. PoCs published by tihomirocrew.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-3437, demonstrating arbitrary physical memory read/write via the `portwell.sys` driver's IOCTL interface. The PoC leverages `MmMapIoSpace` to achieve local privilege escalation (LPE) to SYSTEM.

Description

An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.

Exploits (2)

nomisec WORKING POC
by tihomirocrew · poc
https://github.com/tihomirocrew/portwell-lpe

This repository contains a functional exploit for CVE-2026-3437, demonstrating arbitrary physical memory read/write via the `portwell.sys` driver's IOCTL interface. The PoC leverages `MmMapIoSpace` to achieve local privilege escalation (LPE) to SYSTEM.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Portwell Engineering Toolkits v4.8.2 (portwell.sys)
No auth needed
Prerequisites: Access to a system with the vulnerable Portwell Engineering Toolkits driver installed
mistral-large-3 · analyzed Jun 28, 2026 Full analysis →
github WORKING POC
by tihomirocrew · c++poc
https://github.com/tihomirocrew/cve-2026-3437

This repository contains a functional exploit for CVE-2026-3437, demonstrating arbitrary physical memory read/write operations via a vulnerable driver (PORTWELL_0_1). The PoC interacts with the driver using specific IOCTL codes (0xEA606450 for read, 0xEA60A454 for write) to achieve low-level memory manipulation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: PORTWELL driver (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable driver (\\.\PORTWELL_0_1) · Local execution privileges to interact with the driver
mistral-large-3 · analyzed Jun 15, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0016
EPSS Percentile 5.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119
Status published
Products (3)
portwell/engineering_toolkits 4.8.2
Portwell/Portwell Engineering Toolkits < 4.8.2
Portwell/Portwell Engineering Toolkits v5.0.0
Published Mar 03, 2026
Tracked Since Mar 04, 2026