Executive brief
EaseUS Todo Backup is a data backup and recovery software for Windows systems. A security flaw in one of its system drivers allows a standard user to bypass normal security restrictions and directly read or write to the computer's hard drive. This could allow an attacker to steal sensitive system files, crash the computer, or gain full administrative control over the device.
Technical details
The vulnerability is classified as Improper Privilege Management (CWE-269) within the eudskacs.sys driver (version 20250328). The driver fails to properly validate privileges for IRP_MJ_READ and IRP_MJ_WRITE I/O requests sent to its device object. A local, low-privileged attacker can exploit this to perform arbitrary raw disk reads and writes. This bypasses filesystem permissions, enabling the disclosure of sensitive files like the SAM/SYSTEM hives, causing a denial of service, or achieving local privilege escalation. The exploit requires local access but no user interaction.
Affected products
- EaseUS Todo Backup 1.2.0.1 (driver version 20250328)
Timeline
- 2025-09-10: advisory: NVD publication date
- 2025-09-04: disclosed: Public disclosure date listed in third-party advisory