Minitool develops a focused portfolio of data-recovery and system-utility software, including partition management, file recovery, and backup tools that operate with elevated system privileges. The vulnerabilities observed in this vendor cluster around certificate validation and search-path handling—weakness classes that reflect the trust-anchoring and local-execution context of administrative utilities. Live exploitation activity, severity distribution, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minitool over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38356HIGH MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack. | Sep 19, 2023 | 8.1 | 24 | NO | NO |
CVE-2022-29320HIGH MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level. | May 20, 2022 | 7.8 | 24 | NO | NO |
CVE-2023-38352HIGH MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack. | Sep 19, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-38355HIGH MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack. | Sep 19, 2023 | 8.1 | 22 | NO | NO |
CVE-2023-38354HIGH MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack. | Sep 19, 2023 | 8.1 | 22 | NO | NO |
CVE-2023-38351HIGH MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack. | Sep 19, 2023 | 8.1 | 22 | NO | NO |
CVE-2023-38353MEDIUM MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the mid | Sep 19, 2023 | 5.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minitool.
Media articles that mention a CVE ID that affects a product developed by Minitool — matched by CVE ID, not by vendor name.