Executive brief
Vinchin Backup & Recovery is a data protection solution used by organizations to back up virtual machines, databases, and physical servers. A security flaw in its communication service allows an unauthenticated attacker to send a specially crafted network request that can crash the backup service or potentially allow them to take control of the system. This could lead to a disruption of backup operations and impact the availability of critical data recovery services.
Technical details
A stack-based buffer overflow exists in the 'agentlink_server' service of Vinchin Backup & Recovery. The vulnerability is located within the 'ModuleHandShake' function, where the length of the '_listen_uuid' field is measured using 'strlen()' but subsequently copied into a fixed-length stack buffer using 'strcpy()' without proper bounds checking. An unauthenticated remote attacker can exploit this by sending a crafted request with an oversized '_listen_uuid' value. This allows the attacker to overwrite the saved return address on the stack, leading to a process crash (denial of service) or potential control flow hijacking (remote code execution).
Affected products
- Vinchin Backup & Recovery 9.0 through 9.0.0.86562
Timeline
- 2026-07-08: disclosed: Initial disclosure by Code White GmbH
- 2026-07-09: advisory: CVE published and NVD record created