MiniTool
Products
4- 4 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38356 | Hig | 0.53 | 8.1 | 0.01 | Sep 19, 2023 | MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack. | ||
| CVE-2023-38355 | Hig | 0.53 | 8.1 | 0.01 | Sep 19, 2023 | MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack. | ||
| CVE-2023-38354 | Hig | 0.53 | 8.1 | 0.01 | Sep 19, 2023 | MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack. | ||
| CVE-2023-38352 | Hig | 0.53 | 8.1 | 0.01 | Sep 19, 2023 | MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack. | ||
| CVE-2023-38351 | Hig | 0.53 | 8.1 | 0.01 | Sep 19, 2023 | MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack. | ||
| CVE-2020-36953 | Hig | 0.51 | 7.8 | 0.00 | Jan 26, 2026 | MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject… | ||
| CVE-2022-29320 | Hig | 0.51 | 7.8 | 0.00 | May 20, 2022 | MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level. | ||
| CVE-2023-38353 | Med | 0.38 | 5.9 | 0.00 | Sep 19, 2023 | MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack. | ||
| CVE-2026-15475 | Med | 0.00 | 5.3 | 0.00 | Jul 12, 2026 | A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The… |
- risk 0.53cvss 8.1epss 0.01
MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- risk 0.53cvss 8.1epss 0.01
MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- risk 0.53cvss 8.1epss 0.01
MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
- risk 0.53cvss 8.1epss 0.01
MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
- risk 0.53cvss 8.1epss 0.01
MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
- risk 0.51cvss 7.8epss 0.00
MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject…
- risk 0.51cvss 7.8epss 0.00
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
- risk 0.38cvss 5.9epss 0.00
MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.
- risk 0.00cvss 5.3epss 0.00
A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The…