Executive brief
A security vulnerability exists in Matrix42 Empirum Personal Backup, a tool used by organizations to manage and back up employee workstation data. A local user with standard access can exploit a flaw in how the software communicates internally to run unauthorized commands with the highest level of system authority (SYSTEM). This could allow an attacker to take full control of a managed computer, potentially leading to data theft or further network compromise.
Technical details
A privilege escalation vulnerability exists in PBackupVSS.exe within Matrix42 Empirum Personal Backup. The application creates a named pipe (\\.\pipe\PBackupVSS) with a Discretionary Access Control List (DACL) that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages. By exploiting an untrusted search path (CWE-426), the attacker can trigger the execution of a malicious 'shadow.exe' binary placed in a controlled directory, resulting in arbitrary code execution with SYSTEM privileges. The issue is fixed in versions 25.5 and 26.2.
Affected products
- Matrix42 Empirum Personal Backup 25.4, 26.1
Timeline
- 2026-06-29: advisory
- 2026-06-29: disclosed
- 2026-06-29: patched