A critical vulnerability exists in WatchGuard endpoint security products that could allow a local, authenticated attacker to bypass driver authentication and access sensitive kernel and process memory.
This vulnerability is tracked as CVE-2026-13043 and has a reported CVSS score of 9.3. It affects the Panda Kernel Memory Access Driver (pskmad.sys), as noted in an advisory dated October 5, 2026.
Researcher Juan Sacco discovered the vulnerability in the PSKMAD driver used by Panda Security and WatchGuard products. According to the advisory, Panda confirmed and resolved the issue in October 2026.
However, the vendor’s advisory was not retrievable during verification, leaving the affected product versions, fixed releases, and details on remediation unconfirmed.
The vulnerability arises from a lack of authentication in a driver interface that translates user-controlled requests into privileged kernel operations.
The driver exposes the PSMEMDriver device, which allows user-mode applications to request memory access through input/output control commands. Although the opening procedure includes an extended-attribute handshake called PsOpenPacket000, this vulnerability allows an attacker to bypass the intended access-control gate.
The proof of concept for this vulnerability exercises four operations: memory transfer, entry mapping, entry unmapping, and model-specific register access.
All four operations utilize METHOD_BUFFERED and FILE_ANY_ACCESS. These settings define request handling and IOCTL access requirements. However, they do not inherently determine whether every local user can open the device. Device permissions and the authentication failure are crucial for exploitation.
One demonstrated capability involves reading IA32_LSTAR, a processor register associated with the system call entry point. Revealing this privileged address to user mode can expose kernel address information and potentially undermine kernel address space layout randomization.
Additionally, the driver accepts a target process identifier and virtual address; it maps the requested memory, transfers its contents to the caller, and then releases the mapping.
Research indicates the capability to read page-sized chunks across committed, readable process memory regions, resulting in a hexdump of the target process.
It also reports a memory dumping demonstration of the Local Security Authority Subsystem Service (LSASS) on Windows 11 25H2 with virtualization-based security, hypervisor-protected code integrity, and kernel hardware-enforced stack protection enabled. This demonstration does not imply that every configuration or protected process is equally accessible.
Successful exploitation of this vulnerability could disclose credentials, authentication tokens, session data, private keys, browser information, and application secrets stored in memory.
The demonstrated capabilities primarily indicate information disclosure, rather than verified arbitrary code execution. Installing or launching the driver when it is absent is a separate prerequisite and should not be confused with accessing an already installed vulnerable endpoint component.
Administrators should obtain vendor-confirmed fixed releases and prioritize remediation for affected endpoints. Recommended defensive measures include restricting access to the device, enforcing caller authentication and process-access checks, validating request parameters, removing unnecessary register-reading functionality, and monitoring unexpected access to the PSMEMDriver.
Where operationally feasible, organizations can block the vulnerable driver after confirming compatibility and testing endpoint protection.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…