Full Report
WatchGuard security advisory (AV26-990)
Analysis Summary
# Vulnerability: WatchGuard Endpoint Security Arbitrary Kernel Memory Access
## CVE Details
- **CVE ID:** CVE-2026-13043
- **CVSS Score:** Not explicitly listed in the brief (Typically High/Critical for arbitrary kernel access)
- **CWE:** CWE-306 (Missing Authentication for Critical Function) / CWE-822 (Untrusted Pointer Dereference in Kernel)
## Affected Systems
- **Products:** WatchGuard Endpoint Security (Includes Panda/WatchGuard branded endpoint protection suites)
- **Versions:** All versions prior to 8.00.26.0012
- **Configurations:** Systems running the vulnerable Kernel Memory Access Driver.
## Vulnerability Description
The vulnerability stems from missing authentication within a specific Kernel Memory Access Driver used by WatchGuard Endpoint Security. An attacker or a malicious process can interact with the driver to perform unauthorized reads or writes to arbitrary kernel memory. Because the driver operates at the highest privilege level (Ring 0), this bypasses standard OS security boundaries.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild (based on provided summary).
- **Complexity:** Medium (Requires ability to execute code on the target system to interact with the driver).
- **Attack Vector:** Local (The attacker must have a footprint on the local machine to communicate with the driver).
## Impact
- **Confidentiality:** High (Potential to read sensitive kernel-space data).
- **Integrity:** High (Potential to modify kernel structures, hide processes, or disable security features).
- **Availability:** High (Potential to cause system crashes/BSOD).
## Remediation
### Patches
- **WatchGuard Endpoint Security:** Upgrade to version **8.00.26.0012** or later.
### Workarounds
- No specific workarounds are provided in the advisory; immediate patching is recommended as kernel-level flaws cannot be easily mitigated by configuration changes.
## Detection
- **Indicators of compromise:** Unusual driver calls to the WatchGuard memory driver; presence of unauthorized kernel-level debugging or memory dumping tools.
- **Detection methods and tools:** Monitor system logs for driver errors or unexpected reboots. Use EDR tools to flag non-system processes attempting to interface with kernel drivers.
## References
- **Vendor Advisory:** hxxps[://]psirt[.]watchguard[.]com/CVE-2026-13043
- **WatchGuard Security Portal:** hxxps[://]psirt[.]watchguard[.]com/
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/watchguard-security-advisory-av26-990