# CVE-2026-13043: WatchGuard/Panda Kernel Memory Access Driver (pskmad.sys) Missing Authentication Exposes Kernel and Process Memory

> A missing-authentication flaw (CWE-306) in the Panda Kernel Memory Access Driver (pskmad.sys, device \\.\PSMEMDriver) shipped with WatchGuard Endpoint Security for Windows lets a local user bypass the driver's PsOpenPacket000 handshake and issue privileged commands, disclosing kernel and process memory. A public PoC reportedly dumps LSASS on Windows 11 25H2 with VBS/HVCI/kCET enabled. Fixed in 8.00.26.0012.

- **Published:** 2026-10-11T15:22:06Z
- **Last reviewed:** 2026-10-11T15:22:06Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3315
- **ID:** TL-2026-3315
- **Severity:** CRITICAL (CVSS 9.3)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-13043

## Description

CVE-2026-13043 (CVSS v4.0 9.3, vector CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) is a missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD, pskmad.sys) used by WatchGuard endpoint security products, inherited from Panda Security. The driver exposes a user-mode interface through the device \\.\PSMEMDriver (\Device\PSMEMDriver, \Global??\PSMEMDriver). According to the CNA description, a local, authenticated attacker can bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver, resulting in disclosure of kernel and process memory. Weaknesses recorded against the CVE are CWE-306 (Missing Authentication for Critical Function) and CWE-798 (Use of Hard-coded Credentials); the advisory also maps CAPEC-115 (Authentication Bypass) and CAPEC-194 (Fake the Source of Data).

Per the researcher's write-up (Juan Sacco, exploitpack.com) and the GBHackers coverage, the driver translates user-controlled requests into privileged kernel operations without authenticating the caller. The handshake is an extended-attribute packet named PsOpenPacket000 combined with named synchronization objects (Global\DOGPskMadSec_*, Global\DOGPskMadSignal_*, Global\DOGPskMadReply_*); the magic value is withheld by the researcher. Once bypassed, the IOCTL interface (METHOD_BUFFERED, FILE_ANY_ACCESS, device type 0xB370) exposes four operations: TRANSFER (0xB3702C08), ENTRY_MAP (0xB3702C0C), ENTRY_UNMAP (0xB3702C10) and MSR access (0xB3702C3C). The PoC reads the IA32_LSTAR MSR (0xC0000082, the system call entry point) to defeat kASLR, enumerates the target process virtual-address mappings, and dumps process memory, including LSASS (PID 1020 in the demo), by supplying a target process identifier and virtual address and reading page-sized chunks across committed, readable regions. It is reported to work on fully patched Windows 11 25H2 with VBS, HVCI and kCET enabled, because the read primitive is provided by a legitimately signed vendor driver rather than by a kernel exploit. Memory exposure includes credentials, authentication tokens, session data, private keys, browser data and application secrets.

The analyzed driver sample is pskmad.sys x64, file version 1.1.0.23 (product 1.1.0.45), 63,360 bytes, SHA-256 9bf3b737afa4d4f5e7b00ec749d4b75656ad66d9a2b402e1e81934e95ba7df5b, signed via the Microsoft Windows Hardware Compatibility Publisher, company Panda Security, S.L.U. The vendor PSIRT advisory (published 2026-10-01) lists WatchGuard Endpoint Security for Windows versions prior to 8.00.26.0012 as affected, 8.00.26.0012 as the fixed release, and no documented workaround; no credits are listed in the advisory. The vulnerability requires local code execution or a local authenticated session; no network exploitation is possible.

Exploitation status: GBHackers dates the advisory 2026-10-05 and its article 2026-10-06; the hunt feed described active exploitation, but the article text does not explicitly confirm it, a secondary analysis (Ayi NEDJIMI Consultants, updated 2026-10-11) states no in-the-wild exploitation was confirmed, and the CVE is not listed in CISA KEV as of the sources reviewed. No network IOCs (no IPs/domains, so no BeaconBeagle correlation applicable), no threat-actor attribution and no malware families are published. The pskmad_64.sys driver has been the subject of earlier WatchGuard PSIRT advisories (WGSA-2024-00001, -00002, -00003: pool memory corruption, out-of-bounds write, arbitrary memory read), and the researcher cites older Panda-lineage issues (CVE-2015-1438, CVE-2017-8339, CVE-2023-6330/6331/6332), indicating a recurring weak driver attack surface.

Defensive relevance: a signed security-vendor driver with an unauthenticated read primitive is a bring-your-own-vulnerable-driver (BYOVD)-style credential-theft enabler that bypasses VBS/HVCI protections for user-mode secrets. Defenders should patch to 8.00.26.0012, monitor handles/opens to PSMEMDriver from unexpected processes, watch for LSASS access by non-security tooling, and consider blocking the vulnerable driver hash after compatibility testing.

## MITRE ATT&CK

- T1003.001 LSASS Memory
- T1212 Exploitation for Credential Access
- T1106 Native API
- T1057 Process Discovery
- T1005 Data from Local System

## Sources

- [Critical WatchGuard Endpoint Security Flaw Exposes Kernel and Process Memory (GBHackers)](https://gbhackers.com/critical-watchguard-endpoint-security-flaw-exposes-kernel-and-process-memory/)
- [WatchGuard PSIRT Advisory CVE-2026-13043](https://psirt.watchguard.com/CVE-2026-13043)
- [CVE-2026-13043: Panda Arbitrary Kernel/Process Memory Read (Juan Sacco, exploitpack.com)](https://exploitpack.com/blogs/research/cve-2026-13043-panda-arbitrary-kernel-process-memory-read)
- [OpenCVE: CVE-2026-13043](https://app.opencve.io/cve/CVE-2026-13043)
- [CVE-2026-13043 WatchGuard Kernel Memory analysis (Ayi NEDJIMI Consultants)](https://ayinedjimi-consultants.fr/cve/cve-2026-13043-watchguard-kernel-memory)
- [WatchGuard Endpoint pskmad_64.sys Arbitrary Memory Read Vulnerability (WGSA-2024-00003)](https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00003)
- [WatchGuard Endpoint pskmad_64.sys Pool Memory Corruption Vulnerability (WGSA-2024-00001)](https://www.watchguard.com/de/wgrd-psirt/advisory/wgsa-2024-00001)
- [WatchGuard Endpoint pskmad_64.sys Out of Bounds Write Vulnerability (WGSA-2024-00002)](https://www.watchguard.com/br/wgrd-psirt/advisory/wgsa-2024-00002)
- [Hack.lu 2026: Kernel Primitives to Code Execution on Windows 11 VBS/HVCI/kCET (Juan Sacco)](https://pretalx.com/hack-lu-2026/talk/DBBS3T/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3315
