VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
What happened
AOMEI Backupper is available as a Windows application and can be integrated into enterprise backup workflows or directly used by end users. Overview An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk.
When Secure Boot is disabled, this can be leveraged to execute arbitrary UEFI-level code before the operating system loads. This allows an attacker to bypass OS-level security controls, including HVCI, EDR solutions, and Microsoft Defender.
Description AOMEI Backupper from AOMEI International Network Limited is designed to provide backup and disaster recovery services. The payload can then execute during the UEFI Boot Device Selection (BDS) phase, before operating system security mechanisms are loaded.
Sources & evidence
- CERT/CC Vulnerability Notes Primary / official
VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks โ
https://kb.cert.org/vuls/id/687587