PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages to trigger execution of arbitrary commands with SYSTEM privileges via an untrusted search path. This allows privilege escalation by placing a malicious shadow.exe in a controlled working directory.
References
Configurations
No configuration.
History
17 Jul 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
29 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-276 CWE-426 |
29 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-29 20:17
Updated : 2026-07-17 16:17
NVD link : CVE-2026-57919
Mitre link : CVE-2026-57919
CVE.ORG link : CVE-2026-57919
JSON object : View
Products Affected
No product.
