CVE-2026-56129 is an insufficient access-control vulnerability in the Generic IO & Memory Access driver distributed with Toshiba and Dynabook password utilities. Six exposed IOCTL handlers pass an unvalidated 32-bit physical address to MmMapIoSpace, enabling a non-administrative user-mode process to read or write one, two, or four bytes of physical memory below 4 GiB.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This standalone Windows C++ proof of concept demonstrates physical-memory access through Toshiba's qiomem.sys driver. It is a genuine read/write demonstration rather than a detection-only script, with no evident malicious decoy behavior. No CVE or affected driver version is supplied. The README's claims about CVE assignment and vulnerable-driver blocklist coverage are not independently verified. The seven-file repository contains two executable sources, two supporting headers, one build script, a README, and a .gitignore. acpi.cpp creates a software device with hardware ID ACPI\QCI0701 and waits for user input before removing it. main.cpp discovers the driver's device interface and submits an 11-byte packed buffer containing a 32-bit physical address and DWORD data at offset seven. Reads use IOCTL 0x08012008 and writes use 0x08012014; QWORD operations combine two DWORD requests. superfetch/nt.h defines native Superfetch structures, while superfetch/superfetch.h enables existing token privileges and queries physical ranges and page-frame identities to map virtual addresses to physical addresses. build.bat compiles both programs using MSVC. The demonstration allocates and locks pages, making up to 64 attempts to find one below 4 GiB, then reads and modifies its own page through the driver. The physical-address field truncates addresses to 32 bits, so the helpers cannot safely address memory at or above 4 GiB. QWORD accesses are non-atomic. Broader kernel-memory tampering is a potential consequence of the primitive, but token theft, privilege escalation, persistence, and arbitrary code execution are not implemented or demonstrated. The privilege requirements also mean this code does not establish exploitability from an ordinary unprivileged account. There are no runtime network connections, downloads, or exfiltration endpoints. All HTTPS URLs occur only in documentation. The driver binary is not included. Repository URL, git reference, and archive size were not provided; the listed individual file sizes total 18,923 bytes, while size_bytes is left at 0 to indicate unavailable archive metadata.
This repository is a local Windows exploit/PoC for a vulnerable Toshiba driver, qiomem.sys, that exposes arbitrary physical memory read/write to user mode via device IOCTLs. The repo contains two executables: acpi.cpp creates a fake software ACPI device with hardware ID ACPI\QCI0701 so Plug and Play will load/bind the target driver, and main.cpp locates the driver device interface by GUID, opens it, and issues read/write IOCTLs. The exploit is not remote and does not include a post-exploitation shell; instead it provides a reusable primitive for low physical memory access. Repository structure: README.md explains the vulnerability and usage flow; build.bat compiles both binaries; acpi.cpp handles software device creation through SwDeviceCreate; main.cpp contains the core exploit logic; superfetch/nt.h and superfetch/superfetch.h implement helper code to query Windows Superfetch memory metadata and translate a user virtual allocation to its backing physical address. Core exploit flow in main.cpp: (1) enumerate the qiomem device interface using GUID 020c37d0-a3a6-4069-a640-33480a033c25; (2) open the device path returned by SetupAPI; (3) allocate and lock pages until one is backed by a physical address below 4GB; (4) use NtQuerySystemInformation(SystemSuperfetchInformation) plus PFN queries to translate the chosen virtual address to physical; (5) verify the primitive by reading the page contents through IOCTL 0x8012008; (6) overwrite the same physical memory through IOCTL 0x8012014; and (7) confirm the write via the original virtual mapping. The below-4GB retry logic exists because the driver buffer format only supports a 32-bit physical address field. The exploit is operational rather than just a detector: it performs real device interaction and demonstrates successful physical memory modification. While the sample payload only writes a test constant into a controlled page, the primitive could be adapted for broader kernel exploitation or privilege escalation on affected Windows systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.