PT-2026-53735 · Matrix42 · Empirum
CVSS v3.1
7.8
High
| Vector | AC:L/AV:L/A:H/C:H/I:H/PR:L/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
Matrix42 Empirum versions prior to 25.5
Matrix42 Empirum versions 26.x prior to 26.2
Description
The
PBackupVSS.exe component creates a named pipe at '.pipePBackupVSS' with a Discretionary Access Control List (DACL) that grants GENERIC READ and GENERIC WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted Inter-Process Communication (IPC) messages to trigger the execution of arbitrary commands with SYSTEM privileges. This is achieved via an untrusted search path, allowing the attacker to escalate privileges by placing a malicious shadow.exe file in a controlled working directory.Recommendations
Update Matrix42 Empirum to version 25.5 or later.
Update Matrix42 Empirum version 26.x to version 26.2 or later.
Fix
Incorrect Default Permissions
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Empirum