CVE-2026-45196
7.8Imagination · Graphics DDK
A privilege escalation vulnerability in Imagination Graphics DDK allows a low-privileged local user inside a Host VM to trigger improper GPU register access.
Executive summary
An improper permission handling vulnerability in Imagination Technologies Graphics DDK allows local users to achieve privilege escalation via the GPU firmware.
Vulnerability
This issue is an improper permission handling vulnerability, classified under CWE-280, where kernel software in a Host VM posts improper commands to the GPU firmware. The CVSS vector indicates a local attack vector requiring low privileges and no user interaction.
Business impact
A successful exploit allows a low-privileged local user to escalate privileges and obtain complete control over the affected system. This introduces significant risks of unauthorized data access, system manipulation, and service disruption. The high CVSS score of 7.8 reflects the severity of potential total compromise for virtualized environments utilizing vulnerable driver versions.
Remediation
Immediate Action: Update Imagination Technologies Graphics DDK to version 26.1 RTM2 or later to resolve the underlying permission handling flaw.
Proactive Monitoring: Monitor system logs for unusual local execution patterns or unauthorized attempts to access GPU registers within virtual machines.
Compensating Controls: Restrict local user access levels within virtual machine environments and enforce the principle of least privilege to minimize exposure.
Exploitation status
Public Exploit Available: No (no confirmed public exploit or weaponized module currently exists in the available data).
Analyst recommendation
Given the high severity score and the potential for full system compromise, administrators should treat this vulnerability with urgency. Apply the vendor-provided update to version 26.1 RTM2 or later across all affected virtualized environments as soon as possible to eliminate the privilege escalation vector.