Skip to main content
EPSS 0.2%top 94%

CVE-2026-12780: Improper Access Controls in AOMEI Backupper

0
Critical
VulnerabilityCVE-2026-12780cvecve-2026-12780windowslocal
Published: 09/10/2026 (09/10/2026, 17:46:33 UTC)
Source: CVE Database V5
Vendor/Project: AOMEI
Product: Backupper

Description

Overview An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk. When Secure Boot is disabled, this can be leveraged to execute arbitrary UEFI-level code before the operating system loads. This allows an attacker to bypass OS-level security controls, including HVCI, EDR solutions, and Microsoft Defender. The attack may also enable capture of BitLocker Volume Master Key (VMK) material, depending on the system's BitLocker configuration. Description AOMEI Backupper from AOMEI International Network Limited is designed to provide backup and disaster recovery services. It also helps individuals and businesses to create system images, disk clones, and file backups. AOMEI Backupper is available as a Windows application and can be integrated into enterprise backup workflows or directly used by end users. CVE-2026-12780 : An Incorrect Permission Assignment for Critical Resource (CWE-732) vulnerability in the amwrtdrv.sys kernel driver used by AOMEI Backupper 8.4.0 allows an unprivileged local attacker to achieve UEFI-level arbitrary code execution by directly writing to physical disk devices. The driver creates a world-accessible device object without a security descriptor, therefore allowing any user-mode process to open the device and issue unrestricted write requests. Hence, an attacker can modify disk sectors in the pre-partition gap (LBA 34–2047), inject a malicious UEFI payload, and alter the GPT to reference the payload as an EFI System Partition. The payload can then execute during the UEFI Boot Device Selection (BDS) phase, before operating system security mechanisms are loaded. Impact An attacker with unprivileged local access to a system running AOMEI Backupper 8.4.0 can exploit this vulnerability by opening the world-accessible \\.\mwrtdrv\DISK0 device object and sending specially crafted write commands to an arbitrary physical disk. When Secure Boot is disabled, a successful exploitation allows the attacker to inject UEFI code that executes before the Windows kernel loads, completely bypassing kernel-mode security features including Hyper-V Code Integrity (HVCI), Endpoint Detection and Response (EDR) solutions, Windows Defender, and Hyper-V isolation. On systems using BitLocker with TPM-only protection, this attack vector enables evil maid attacks whereby VMK credentials can be captured during the pre-boot phase Boot Device Selection (BDS) phase. Solution Please see the Vendor Information section for patches provided by AOMEI International Network Limited to address this issue. CERT/CC recommends that AOMEI Backupper users update to a version that includes the corrected amwrtdrv.sys driver and implements appropriate access controls. Users who cannot immediately apply the available update should consider uninstalling AOMEI Backupper. Alternatively, users may disable the amwrtdrv.sys service by changing its start type from AUTO_START to disabled. Enabling Secure Boot in UEFI firmware settings provides additional defense in depth by requiring signed bootloaders, but it does not address the underlying driver vulnerability. Acknowledgements Thank you to SiCk / afflicted.sh for reporting this vulnerability. This document was written by Vijay Sarvepalli. Vendor Information One or more vendors are listed for this advisory. Please reference the full report for more information. References https://aomeitech.com https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language Other Information CVE IDs: Date Public: 2026-09-10 Date First Published: 2026-09-10 Date Last Updated: 2026-09-10 17:46 UTC Document Revision: 1 About vulnerability notes Contact us about this vulnerability Provide a vendo…

CVSS v4.0

Score 8.5high

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Affected software

AOMEI

Backupper

Affected versions
=8.0=8.1=8.2=8.3.0
CPE configurations
cpe:2.3:a:aomei:backupper:*:*:*:*:*:*:*:*

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/28/2026, 21:52:38 UTC

Technical Analysis

This vulnerability affects the kernel driver component (amwrtdrv.sys) of AOMEI Backupper versions up to 8.3.0. It involves improper access controls that could allow a local attacker with limited privileges to manipulate the driver, potentially leading to unauthorized actions with high impact on confidentiality, integrity, and availability. The exploit requires local access and no user interaction. The vulnerability has been publicly disclosed, but the vendor has not issued any response or patch. No known exploits are currently observed in the wild.

Potential Impact

Successful exploitation can lead to improper access control bypass in the kernel driver, potentially allowing a local attacker to perform unauthorized actions that compromise system confidentiality, integrity, and availability. The attack requires local access and limited privileges but does not require user interaction.

Mitigation Recommendations

No official patch or remediation is currently available from the vendor, who has not responded to the disclosure. Users should restrict local access to trusted users only and monitor for suspicious local activity. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulDB
Date Reserved
2026-06-20T09:36:11.510Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a3778eb9c760d8add8aba4a

Added to database: 06/21/2026, 05:38:51 UTC

Last enriched: 06/28/2026, 21:52:38 UTC

Last updated: 09/19/2026, 10:01:29 UTC

Views: 242

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses