CVE-2026-57919 Details
Description
PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages to trigger execution of arbitrary commands with SYSTEM privileges via an untrusted search path. This allows privilege escalation by placing a malicious shadow.exe in a controlled working directory.
A privilege escalation vulnerability has been identified in Matrix42 Empirum Personal Backup versions prior to 25.5 and 26.x prior to 26.2. The vulnerability arises because PBackupVSS.exe creates a named pipe with a discretionary access control list (DACL) that allows GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. This oversight enables low-privileged local attackers to connect to the pipe and send crafted inter-process communication (IPC) messages, triggering the execution of arbitrary commands with SYSTEM privileges. Exploitation involves placing a malicious shadow.exe in a controlled working directory, taking advantage of an untrusted search path.
Users can update to Empirum versions 25.5 or 26.2 to address this vulnerability. Additionally, applying the hotfix for PRB39539 is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 29, 2026CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | CISA-ADP |
| CWE-426 | Untrusted Search Path | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Matrix42 Empirum Personal Backup | 25.4 26.1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | CVE Modified | [email protected] |
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 29, 2026 | New CVE Received | [email protected] |
Volerion