Junglewise Threat Intelligence

CVE-2025-50892: EaseUS Todo Backup privilege escalation in eudskacs.sys driver

CVE-2025-50892 · Severity: high · CVSS 7.8 · Published 2025-09-10

Executive brief

EaseUS Todo Backup is a data backup and recovery software for Windows systems. A security flaw in one of its system drivers allows a standard user to bypass normal security restrictions and directly read or write to the computer's hard drive. This could allow an attacker to steal sensitive system files, crash the computer, or gain full administrative control over the device.

Technical details

The vulnerability is classified as Improper Privilege Management (CWE-269) within the eudskacs.sys driver (version 20250328). The driver fails to properly validate privileges for IRP_MJ_READ and IRP_MJ_WRITE I/O requests sent to its device object. A local, low-privileged attacker can exploit this to perform arbitrary raw disk reads and writes. This bypasses filesystem permissions, enabling the disclosure of sensitive files like the SAM/SYSTEM hives, causing a denial of service, or achieving local privilege escalation. The exploit requires local access but no user interaction.

Affected products

  • EaseUS Todo Backup 1.2.0.1 (driver version 20250328)

Timeline

  • 2025-09-10: advisory: NVD publication date
  • 2025-09-04: disclosed: Public disclosure date listed in third-party advisory

References