CVE-2026-12780

Published Jun 21, 2026

Last updated 19 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-12780 describes a vulnerability found in AOMEI Backupper, specifically affecting versions up to 8.3.0. The flaw resides within an unknown function in the `amwrtdrv.sys` kernel driver component, leading to improper access controls. This vulnerability is classified as a local privilege escalation, meaning an attacker would need local access to the system to exploit it. The exploit has been publicly disclosed and may be actively utilized. Users are advised to apply vendor patches and update AOMEI Backupper to the latest version to address this issue.

Description
A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Source
cna@vuldb.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.1
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

CVSS 2.0

Type
Secondary
Base score
6.8
Impact score
10
Exploitability score
3.1
Vector string
AV:L/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

cna@vuldb.com
CWE-266

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

9