Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from space KNOW and version X

Background:

psmounterex.sys is a kernel mode driver that enables Macrium backups to be mounted and accessed by file explorer as a 'virtual drive'.

CVE-2023-43896:  https://nvd.nist.gov/vuln/detail/CVE-2023-43896

This issue regards being able to craft input such that a non-elevated process could gain access to kernel space memory outside that used by the mounting operation. This would enable a carefully crafted non-elevated process to trigger a system crash. Theoretically this class of flaw could be used as a privilege escalation attack stepping stone by a sophisticated actor.

This issue has been fixed in :


EditionBuildDateRelease Notes
Macrium Reflect Home, Workstation, Server, Server Plusv8.1.76759th October 2023____________________https://updates.macrium.com/reflect/v8/v8.1.7675/details8.1.7675.htm
Macrium Reflect Free Editionv8.0.769011th October 2023https://updates.macrium.com/reflect/v8/v8.0.7690/details8.0.7690.htm
Macrium Site Managerv8.1.769516th October 2023Release Notes#8.1.7695-2023-10-16



We encourage all users of Macrium Reflect or Macrium Site Manager to update at the earliest opportunity.

Acknowledgments 

We thank Northwave Cybersecurity for bringing this to our attention:

https://northwave-cybersecurity.com/hs-search-results?term=macrium&type=SITE_PAGE&type=BLOG_POST&type=LISTING_PAGE