CVE-2026-12217: DVDFab Virtual Drive Signed Kernel Driver dvdfabio.sys privileges management
A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the component Signed Kernel Driver. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
DVDFab Virtual Drive 2.0.0.5 includes a signed Windows kernel driver, dvdfabio.sys, with improper privilege management. A local user could abuse it to gain higher privileges on the machine. This is most urgent where the product is installed on workstations or servers used by standard users.
Executive priority
Treat as high priority for affected endpoints, especially shared workstations and sensitive systems. The issue is local, not remotely reachable by itself, but it can turn limited access into broader endpoint compromise.
Technical view
CVE-2026-12217 affects DVDFab Virtual Drive 2.0.0.5, specifically the signed kernel driver dvdfabio.sys. The issue is classified under CWE-266 and CWE-269. CVSS 4.0 is 8.5 with local attack vector, low complexity, low privileges required, no user interaction, and high confidentiality, integrity, and availability impact.
Likely exposure
Exposure appears limited to Windows systems with DVDFab Virtual Drive 2.0.0.5 installed and the dvdfabio.sys driver present or loaded. The sources do not identify other affected versions.
Exploitation context
The vulnerability requires local access and low privileges. Public disclosure of exploit information is reported by VulDB, but CISA KEV is not indicated and the provided sources do not confirm active exploitation in the wild.
Researcher notes
Evidence is currently centered on VulDB and a public disclosure reference. The affected version is listed as 2.0.0.5 only. No official vendor fix, workaround, or advisory is included in the provided sources.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-266: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
CWE-269: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
4CVSS vectors
6Timeline events
0ADP providers
6Source links
CVSS vector scores
4 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-266 · source CWE mapping
Incorrect Privilege Assignment
Incorrect Privilege Assignment represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
Improper Privilege Management represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.