Like a vault whose combination is etched on the door, this EDR driver authenticates callers with a public constant anyone can copy
CVE-2026-13043 is a missing-authentication flaw in the Panda Kernel Memory Access Driver (pskmad_64.sys), shipped with WatchGuard EPDR, Panda AD360, and Panda Dome for Windows. All versions prior to 8.00.26.0012 are affected. The driver exposes a privileged IOCTL interface behind a user-mode authentication handshake, but that handshake is fatally broken: the "secret" is a hardcoded public constant (0xfafaffff) that any unsigned process running as a standard (non-admin) user can supply. Once past the gate, the caller can issue arbitrary privileged commands to the driver — the documented IOCTL 0xB3702C08 reads arbitrary kernel and process memory with attacker-controlled PID, address, offset, and length. The CVSS 4.0 vector scores integrity and availability as High, indicating the bypassed auth also exposes write and corruption primitives consistent with the same IOCTL surface that carried CVE-2023-6330 (pool overflow) and CVE-2023-6331 (OOB write) in earlier driver versions.
WatchGuard assigned a CVSS 4.0 score of 9.3 (AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) but published no CVSS 3.1 baseline. The 4.0 vector rates subsequent-system impact as High across confidentiality, integrity, and availability — acknowledging the chain extends past the driver itself. This is warranted: pskmad_64.sys runs at ring 0 as part of the endpoint security stack. Compromising its auth means an attacker bypasses the very detection tool deployed to stop them, gains a kernel read primitive useful for KASLR defeat and credential extraction, and can chain the write-class IOCTLs for full kernel code execution. The secondary CWE-798 (Use of Hard-Coded Credentials) classification confirms the hardcoded constant is the root cause. The vendor's 9.3 is not inflated — this is a security-agent-class vulnerability with a trivially forgeable gate.
5 steps from start to impact.
Obtain local user session on target endpoint
- Local code execution as a standard (non-admin) Windows user
- Target host runs WatchGuard EPDR, Panda AD360, or Panda Dome with version < 8.00.26.0012
- Requires prior initial access — the attacker must already be on the endpoint via phishing, exploit, or compromised credentials
- Hosts without WatchGuard/Panda endpoint security are unaffected (~98.4% of the endpoint market per 6sense market-share data)
Forge PSKMAD driver authentication handshake
\\Device\\PSMEMDriver via CreateFile and supplies an extended-attribute packet (PsOpenPacket000). The driver writes a challenge into shared memory containing public constants and the caller's PID. The attacker writes the hardcoded success constant 0xfafaffff into the response section. The driver accepts this as valid authentication and marks the caller's handle as privileged. No Panda-signed code is loaded; no admin rights are required. The full protocol is documented in LOLDrivers issue #434.- Ability to create named kernel objects and open device handles (any interactive user)
- Knowledge of the authentication protocol (publicly documented in LOLDrivers issue #434)
- The protocol requires custom tooling — no turnkey weaponized exploit is publicly available as of 2026-10-02, though the documentation is sufficient for any competent offensive developer
Issue arbitrary kernel memory read/write via privileged IOCTLs
0xB3702C08, specifying target process ID, base address, offset, and length. The driver validates addresses against MmHighestUserAddress and MmIsAddressValid, then copies kernel memory into the output buffer — a full arbitrary-read primitive. The same authenticated handle likely grants access to write-class IOCTLs (the same surface that carried CVE-2023-6330 pool overflow and CVE-2023-6331 OOB write), enabling arbitrary kernel memory corruption and code execution at ring 0.- Successfully forged PSKMAD authentication from Step 2
- MmIsAddressValid check prevents reads of unmapped pages but does not restrict which mapped kernel pages can be read
- The write primitives require knowledge of specific IOCTL codes beyond the documented 0xB3702C08, adding marginal complexity
Extract credentials from kernel memory and defeat KASLR
ntoskrnl) is trivially leaked from kernel structures, defeating KASLR for subsequent write-primitive exploitation.- Kernel read primitive from Step 3
- Target host is domain-joined with cached credentials (typical enterprise deployment)
- Credential Guard with full VBS enrollment isolates LSA secrets in a secure enclave unreachable via kernel reads
- Standalone workstations without domain credentials limit blast radius to host-local secrets
Escalate to SYSTEM and pivot laterally toward domain compromise
- Extracted domain credentials with lateral-movement value from Step 4, OR kernel write primitive for local SYSTEM escalation
- Network paths permitting SMB, RPC, or LDAP to other domain members
- Network microsegmentation limits lateral movement paths between tiers
- MFA on privileged accounts prevents credential reuse for interactive sessions
- Tiered administration (PAW model) reduces the probability of Tier 0 credentials on Tier 1/2 hosts
0xfafaffff constant with a proper cryptographic challenge-response mechanism. For cloud-managed deployments, push the update policy from WatchGuard Cloud console. For on-premises managed endpoints, deploy via the management server. Per the noisgate CRITICAL mitigation SLA, deploy within 3 days. Since the patch IS the mitigation, the noisgate remediation SLA (90 days) is met simultaneously. Verify rollout across all managed endpoints by checking driver file version or product version in your asset inventory.Computer Configuration > Administrative Templates > System > Device Guard > Turn on Virtualization Based Security with Credential Guard Configuration set to Enabled with UEFI lock. Requires Windows 10/11 Enterprise or Server 2016+ with compatible CPU and firmware. Deploy within 3 days per noisgate CRITICAL mitigation SLA as a defense-in-depth measure while patching.Allow log on locally to restrict to only necessary service and administrator accounts. For kiosk or single-purpose endpoints, apply AppLocker or WDAC to prevent execution of unsigned binaries. This raises the bar from 'any user who can run code' to 'a compromised authorized user on a locked-down host' — meaningful but not a full block since phishing still lands in authorized user contexts. Deploy within 3 days per noisgate CRITICAL mitigation SLA.\\Device\\PSMEMDriver device object. Alert on any non-WatchGuard process (i.e., processes not signed by Panda Security S.L.U.) invoking IOCTLs on this device. This is detective, not preventive — it will not stop exploitation but will provide post-compromise forensic evidence and near-real-time alerting. Requires custom development or an EDR platform with kernel callback hooks that can filter third-party driver IOCTLs. Deploy within 3 days per noisgate CRITICAL mitigation SLA as a detection stopgap.- Microsoft Vulnerable Driver Blocklist (WDAC/HVCI driver blocklist) — Only blocks BYOVD scenarios where an attacker side-loads a copy of pskmad_64.sys. Does nothing when the driver is legitimately installed and running as part of WatchGuard endpoint security. The driver is validly signed by Panda Security S.L.U. and loads through the product's normal installation path.
- Network segmentation and firewall rules — This is a local kernel driver vulnerability (AV:L). No network traffic is involved in the PSKMAD authentication forgery or IOCTL abuse. Segmentation limits lateral movement *after* credential theft (Step 5) but does not prevent Steps 2-4.
- RunAsPPL for LSASS — The kernel read primitive bypasses PPL entirely by reading process memory through a ring-0 IOCTL rather than opening a userland handle to the LSASS process. RunAsPPL protects against
NtReadVirtualMemorycalls, not against kernel-mode memory copies. - Uninstalling WatchGuard/Panda endpoint security — While this removes the vulnerable driver, it also removes endpoint detection and response capability entirely. This trades one vulnerability for total loss of endpoint visibility. Only viable if you are actively migrating to a different EDR and can ensure continuous coverage during the transition.
The supporting signals.
| In-the-wild exploitation | No known exploitation. Not listed on CISA KEV as of 2026-10-02. No threat actor campaigns or active exploitation observed. Disclosed only 1 day ago (2026-10-01). However, the underlying authentication protocol was publicly documented in LOLDrivers issue #434 prior to CVE assignment — threat actors with access to that documentation could have developed exploits before the CVE was published. |
|---|---|
| Proof-of-concept availability | Partial — protocol fully documented, no turnkey PoC. LOLDrivers issue #434 details the complete forgeable authentication protocol: the PsOpenPacket000 extended-attribute structure, the 0xfafaffff success constant, and the IOCTL 0xB3702C08 parameters (PID, base, offset, length). This is a recipe, not a compiled weapon — but it is sufficient for a competent developer to build a working exploit in hours. No weaponized PoC found on pocindex.io, GitHub (no repos named CVE-2026-13043), ExploitDB, Metasploit, or Nuclei templates as of 2026-10-02. |
| EPSS score | Not yet scored. CVE published 2026-10-01; the FIRST EPSS model has not yet ingested this CVE. Given the detailed public protocol documentation and kernel-mode impact, expect a moderate-to-high EPSS once scored (estimate >50th percentile based on comparable local kernel vulns with public PoC details). |
| KEV status | Not listed on CISA Known Exploited Vulnerabilities catalog as of 2026-10-02. |
| CVSS vector | CVSS 4.0: 9.3 (Critical) — CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H. Local attack vector, low privilege required (standard user), no user interaction, full impact across confidentiality, integrity, and availability including subsequent systems. No CVSS 3.1 vector published. Approximate CVSS 3.1 equivalent: AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H = 8.8. |
| Affected versions | All WatchGuard Endpoint Security versions < 8.00.26.0012, including WatchGuard EPDR, Panda AD360, and Panda Dome for Windows. The kernel driver pskmad_64.sys versions through at least 1.1.0.23 carry the forgeable authentication. Earlier driver version 1.1.0.21 also carried CVE-2023-6330/6331/6332 (patched in product version 8.00.22.0023). |
| Fixed version | WatchGuard Endpoint Security 8.00.26.0012 (covers EPDR and AD360). Panda Dome fixed version not separately confirmed but expected in a parallel release. Cloud-managed deployments may receive auto-updates; on-premises managed endpoints require a policy push from the management console. |
| Scanning / exposure | Local vulnerability — not internet-scannable. Shodan, GreyNoise, Censys, and FOFA are not applicable. Exposure equals the installed base of WatchGuard/Panda endpoint products. WatchGuard holds approximately 1.63% endpoint security market share per 6sense. Customer base skews SMB/MSP: 50% small business (<50 employees), 30% mid-size, ~10% enterprise per TrustRadius. |
| Disclosure timeline | CVE reserved 2026-06-23 by WatchGuard. Published 2026-10-01. Approximately 100-day coordinated disclosure window. |
| Researcher / org | Not publicly attributed for CVE-2026-13043 specifically. Prior pskmad_64.sys research (CVE-2023-6330/6331/6332) was conducted by Andreas Klopsch at Sophos during APT simulation testing. The LOLDrivers issue #434 contributor independently documented the forgeable auth protocol for the current 1.1.0.23 driver version. The driver is listed as Vulnerable in the LOLDrivers catalog. |
Sources.
- WatchGuard PSIRT Advisory — CVE-2026-13043
- LOLDrivers Issue #434 — Forgeable PSKMAD Authentication Protocol
- LOLDrivers Catalog — pskmad_64.sys
- Sophos Blog — Multiple Vulnerabilities in Widely Used Security Driver
- SecurityWeek — WatchGuard/Panda Vulnerabilities Lead to Code Execution
- CVE Record — CVE-2026-13043 (ThreatInt)
- Strix AI — CVE-2026-13043 Analysis
- 6sense — WatchGuard Endpoint Security Market Share
Why this verdict
- Kernel-mode security agent floor: The bug is *in*
pskmad_64.sys, a ring-0 kernel driver that IS the endpoint security product's kernel component. 100% of WatchGuard/Panda endpoint installs include this driver — every installation occupies the "kernel-mode security agent" high-value role. Per noisgate deployment-role rules, the verdict floor is CRITICAL when the affected component is canonically a kernel-mode agent and the chain plausibly reaches domain-scale impact. - Trivially forgeable authentication: The driver's access-control handshake relies on a hardcoded public constant (
0xfafaffff) fully documented in LOLDrivers issue #434. Forging authentication requires no admin rights, no Panda-signed code, and no exploit-development skill beyond reading the protocol spec. This is effectively zero friction at the authentication-bypass step — a rare and dangerous condition for a kernel interface. - Standard-user to kernel primitive (PR:L): The CVSS 4.0 vector specifies PR:L, meaning any local user — not just admin — gains arbitrary kernel memory access. This is a critical upgrade from the 2023-era pskmad CVEs (CVE-2023-6330/6331/6332) which all required administrator privileges. A standard user reading and potentially writing kernel memory bypasses PPL, LSASS access monitoring, RunAsPPL, and most EDR credential-theft detection — the primary defensive controls against post-compromise escalation.
- Role multiplier: On a domain-joined Windows endpoint (the typical role for enterprise WatchGuard EPDR deployments — roughly 10% of WatchGuard's customer base per TrustRadius), the documented chain succeeds: local user session → forged PSKMAD auth → kernel read → credential extraction bypassing PPL → pass-the-hash/pass-the-ticket lateral movement → domain compromise. Blast radius is domain-scale. On a standalone SMB workstation (majority of installs), blast radius is host-level including full EDR bypass and local SYSTEM escalation. The domain-joined enterprise scenario floors the verdict at CRITICAL because the chain reaches domain takeover and the component is canonically a kernel-mode agent.
- EDR self-defeat compounding factor: The attacker abuses the very driver deployed to detect them. Credential theft via kernel IOCTL does not trigger LSASS access alerts, process injection alerts, memory-scanning hooks, or any standard EDR behavioral rule. The agent is architecturally blind to abuse of its own driver's IOCTL interface. This means the post-exploitation detection gap compounds with the escalation primitive.
- Friction acknowledged — local access required: The attacker must already have local code execution on the endpoint (post-initial-access). This is meaningful friction that prevents mass unauthenticated remote exploitation. However, per noisgate floor rules, this friction does NOT break the CRITICAL floor for a kernel-mode security agent vulnerability because (a) every post-exploitation framework delivers local user sessions as step 1, (b) 100% of installs are in the high-value role, and (c) the chain to domain compromise is documented and direct.
Why not higher?
The score is already CRITICAL at 9.0. A 9.5+ would require unauthenticated remote exploitation, wormable propagation, or zero-click network-facing attack surface. This vulnerability requires local access and a standard user session — meaningful friction that caps the score. The primary documented primitive is kernel read; while the CVSS vector implies write capability through the same bypassed auth, direct confirmation of a weaponized write IOCTL for this specific CVE version is not yet public, adding marginal uncertainty to the full privilege-escalation path.
Why not lower?
The deployment-role floor is CRITICAL because the bug is IN a kernel-mode security agent, 100% of installs occupy that role by definition, and the chain plausibly reaches domain takeover on enterprise deployments via credential extraction from kernel memory. Breaking the floor would require evidence that <1% of WatchGuard Endpoint Security installs run as kernel-mode agents — which is structurally impossible since pskmad_64.sys IS the kernel component of every installation. The trivially forgeable authentication (a single hardcoded constant), PR:L requirement (standard user, not admin), and EDR self-defeat characteristics further reinforce the severity. The LOLDrivers issue #434 provides the complete protocol specification, making weaponization a matter of engineering hours, not research months.
Crowdsourced verification payload.
Run on each target Windows endpoint where WatchGuard or Panda endpoint security may be installed. No admin rights required for driver detection; admin helps with registry fallback. Invoke: powershell -ExecutionPolicy Bypass -File .\Check-CVE-2026-13043.ps1. Outputs VULNERABLE, PATCHED, or UNKNOWN with exit codes 1, 0, or 2.
<# CVE-2026-13043 Checker
WatchGuard/Panda PSKMAD Missing Authentication
Fixed in WatchGuard Endpoint Security >= 8.00.26.0012
Exit 0=PATCHED Exit 1=VULNERABLE Exit 2=UNKNOWN
#>
$ErrorActionPreference = 'SilentlyContinue'
# --- Step 1: Locate pskmad driver ---
$driver = $null
$searchDirs = @(
"$env:SystemRoot\System32\drivers",
"$env:ProgramFiles\Panda Security",
"${env:ProgramFiles(x86)}\Panda Security",
"$env:ProgramFiles\WatchGuard"
)
foreach ($dir in $searchDirs) {
if (-not (Test-Path $dir)) { continue }
$hit = Get-ChildItem -Path $dir -Filter 'pskmad*.sys' -Recurse -ErrorAction SilentlyContinue |
Select-Object -First 1
if ($hit) { $driver = $hit; break }
}
if (-not $driver) {
Write-Output 'UNKNOWN - pskmad driver not found. WatchGuard/Panda endpoint security does not appear to be installed.'
exit 2
}
Write-Output "[*] Driver found: $($driver.FullName)"
Write-Output "[*] Driver file version: $($driver.VersionInfo.FileVersion)"
# --- Step 2: Determine product version ---
$prodVer = $null
$uninstPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
foreach ($rp in $uninstPaths) {
$match = Get-ItemProperty $rp 2>$null |
Where-Object { $_.DisplayName -match 'WatchGuard|Panda.*(EPDR|AD360|Dome|Endpoint|Protection)' } |
Select-Object -First 1
if ($match -and $match.DisplayVersion) {
$prodVer = $match.DisplayVersion
Write-Output "[*] Matched product: $($match.DisplayName)"
break
}
}
if (-not $prodVer) {
$regFallback = @('HKLM:\SOFTWARE\Panda Security\Setup',
'HKLM:\SOFTWARE\WOW6432Node\Panda Security\Setup')
foreach ($rk in $regFallback) {
if (Test-Path $rk) {
$v = (Get-ItemProperty $rk -Name 'Version' 2>$null).Version
if ($v) { $prodVer = $v; break }
}
}
}
if (-not $prodVer) {
Write-Output 'UNKNOWN - pskmad driver is present but product version could not be determined.'
Write-Output ' Manually verify product version >= 8.00.26.0012.'
exit 2
}
Write-Output "[*] Product version: $prodVer"
# --- Step 3: Compare to fixed version 8.00.26.0012 ---
try {
$cleaned = $prodVer -replace '[^\d.]', ''
$current = [version]$cleaned
$fixed = [version]'8.0.26.12'
if ($current -ge $fixed) {
Write-Output "PATCHED - version $prodVer >= 8.00.26.0012"
exit 0
} else {
Write-Output "VULNERABLE - version $prodVer < 8.00.26.0012 (CVE-2026-13043)"
exit 1
}
} catch {
Write-Output "UNKNOWN - could not parse version string '$prodVer'. Manual review required."
exit 2
}