CVE-2026-3437
HIGHPortwell Engineering Toolkits 4.8.2 - Memory Corruption
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-3437. PoCs published by tihomirocrew.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-3437, demonstrating arbitrary physical memory read/write operations via a vulnerable driver (PORTWELL_0_1). The PoC interacts with the driver using specific IOCTL codes (0xEA606450 for read, 0xEA60A454 for write) to achieve low-level memory manipulation.
Description
An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.
Exploits (1)
This repository contains a functional exploit for CVE-2026-3437, demonstrating arbitrary physical memory read/write operations via a vulnerable driver (PORTWELL_0_1). The PoC interacts with the driver using specific IOCTL codes (0xEA606450 for read, 0xEA60A454 for write) to achieve low-level memory manipulation.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H