Junglewise Threat Intelligence

CVE-2026-57919: Matrix42 Empirum privilege escalation in PBackupVSS named pipe

CVE-2026-57919 · Severity: high · CVSS 7.8 · Published 2026-06-29

Executive brief

A security vulnerability exists in Matrix42 Empirum Personal Backup, a tool used by organizations to manage and back up employee workstation data. A local user with standard access can exploit a flaw in how the software communicates internally to run unauthorized commands with the highest level of system authority (SYSTEM). This could allow an attacker to take full control of a managed computer, potentially leading to data theft or further network compromise.

Technical details

A privilege escalation vulnerability exists in PBackupVSS.exe within Matrix42 Empirum Personal Backup. The application creates a named pipe (\\.\pipe\PBackupVSS) with a Discretionary Access Control List (DACL) that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages. By exploiting an untrusted search path (CWE-426), the attacker can trigger the execution of a malicious 'shadow.exe' binary placed in a controlled directory, resulting in arbitrary code execution with SYSTEM privileges. The issue is fixed in versions 25.5 and 26.2.

Affected products

  • Matrix42 Empirum Personal Backup 25.4, 26.1

Timeline

  • 2026-06-29: advisory
  • 2026-06-29: disclosed
  • 2026-06-29: patched

References