WatchGuard disclosed a critical flaw in Endpoint Security for Windows, tracked as CVE-2026-13043, that affects versions before 8.00.26.0012. INCIBE-CERT says a local authenticated attacker could abuse the kernel memory access driver to read kernel and other-process memory.
The bug is an authentication bypass in the protection driver: the driver is supposed to check whether a caller is allowed to issue privileged commands, but the flaw lets a logged-in user skip that gate and ask for memory it should not reveal. That can leak system internals, credentials, or other sensitive data already resident on the endpoint.
For Windows fleets that rely on WatchGuard’s kernel driver as part of endpoint protection, the trust boundary is the driver itself, not just the surrounding app. A local foothold on an affected machine can become a memory-disclosure problem even without a broader compromise.
Risolta vulnerabilità in WatchGuard Endpoint Security
WatchGuard ha rilasciato aggiornamenti di sicurezza per sanare una vulnerabilità con gravità "critica" in Endpoint Security per Windows, soluzione dedicata alla protezione dei dispositivi terminali.