CVE-2026-3437

HIGH

Portwell Engineering Toolkits 4.8.2 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-3437. PoCs published by tihomirocrew.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-3437, demonstrating arbitrary physical memory read/write operations via a vulnerable driver (PORTWELL_0_1). The PoC interacts with the driver using specific IOCTL codes (0xEA606450 for read, 0xEA60A454 for write) to achieve low-level memory manipulation.

Description

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.

Exploits (1)

github WORKING POC
by tihomirocrew · c++poc
https://github.com/tihomirocrew/cve-2026-3437

This repository contains a functional exploit for CVE-2026-3437, demonstrating arbitrary physical memory read/write operations via a vulnerable driver (PORTWELL_0_1). The PoC interacts with the driver using specific IOCTL codes (0xEA606450 for read, 0xEA60A454 for write) to achieve low-level memory manipulation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: PORTWELL driver (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable driver (\\.\PORTWELL_0_1) · Local execution privileges to interact with the driver
devstral-2 · analyzed Jun 15, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource government-resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-062-04

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 1.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119
Status published
Products (1)
portwell/engineering_toolkits 4.8.2
Published Mar 03, 2026
Tracked Since Mar 04, 2026