AI description
CVE-2026-12780 describes a vulnerability found in AOMEI Backupper, specifically affecting versions up to 8.3.0. The flaw resides within an unknown function in the `amwrtdrv.sys` kernel driver component, leading to improper access controls. This vulnerability is classified as a local privilege escalation, meaning an attacker would need local access to the system to exploit it. The exploit has been publicly disclosed and may be actively utilized. Users are advised to apply vendor patches and update AOMEI Backupper to the latest version to address this issue.
- Description
- A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
- Source
- cna@vuldb.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 7.1
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Secondary
- Base score
- 6.8
- Impact score
- 10
- Exploitability score
- 3.1
- Vector string
- AV:L/AC:L/Au:S/C:C/I:C/A:C
- cna@vuldb.com
- CWE-266
- Hype score
- Not currently trending
csirt_it: โผ #Aomei: disponibili #PoC per lo sfruttamento delle CVE-2026-12778, CVE-2026-12779 e CVE-2026-12780 Rischio: ๐ Tipologia: ๐ธ Elevation of Privilege ๐ธ Data Manipulation ๐ https://t.co/hVJ7xJQhY8 โ Monitorare il sito del vendor https://t.co/8mgSyYzo49
@Vulcanux_
22 Jun 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
โผ #Aomei: disponibili #PoC per lo sfruttamento delle CVE-2026-12778, CVE-2026-12779 e CVE-2026-12780 Rischio: ๐ Tipologia: ๐ธ Elevation of Privilege ๐ธ Data Manipulation ๐ https://t.co/tJJGGdsBjo โ Monitorare il sito del vendor https://t.co/AgmlKeKyEd
@csirt_it
22 Jun 2026
706 Impressions
0 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
Utilized LLM and discovered kernel drivers' vulnerabilities, 8 of them are already credited, all of them are LPE vulnerabilities: CVE-2026-12217, CVE-2026-12778, CVE-2026-12779, CVE-2026-12780, CVE-2026-12781, CVE-2026-12782, CVE-2026-12784, CVE-2026-12786
@senzee1984
20 Jun 2026
5137 Impressions
2 Retweets
47 Likes
25 Bookmarks
1 Reply
0 Quotes