{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/687587#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nAn incorrect permissions assignment vulnerability in the `amwrtdrv.sys` kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk. When Secure Boot is disabled, this can be leveraged to execute arbitrary UEFI-level code before the operating system loads. This allows an attacker to bypass OS-level security controls, including HVCI, EDR solutions, and Microsoft Defender. The attack may also enable capture of BitLocker Volume Master Key (VMK) material, depending on the system's BitLocker configuration.\r\n\r\n### Description\r\nAOMEI Backupper from AOMEI International Network Limited is designed to provide backup and disaster recovery services. It also helps individuals and businesses to create system images, disk clones, and file backups. AOMEI Backupper is available as a Windows application and can be integrated into enterprise backup workflows or directly used by end users.\r\n\r\n**CVE-2026-12780**: An Incorrect Permission Assignment for Critical Resource (CWE-732) vulnerability in the `amwrtdrv.sys` kernel driver used by AOMEI Backupper 8.4.0 allows an unprivileged local attacker to achieve UEFI-level arbitrary code execution by directly writing to physical disk devices. The driver creates a world-accessible device object without a security descriptor, therefore allowing any user-mode process to open the device and issue unrestricted write requests. Hence, an attacker can modify disk sectors in the pre-partition gap (LBA 34–2047), inject a malicious UEFI payload, and alter the GPT to reference the payload as an EFI System Partition. The payload can then execute during the UEFI Boot Device Selection (BDS) phase, before operating system security mechanisms are loaded.\r\n\r\n### Impact\r\n\r\nAn attacker with unprivileged local access to a system running AOMEI Backupper 8.4.0 can exploit this vulnerability by opening the world-accessible `\\\\.\\mwrtdrv\\DISK0` device object and sending specially crafted write commands to an arbitrary physical disk. When Secure Boot is disabled, a successful exploitation allows the attacker to inject UEFI code that executes before the Windows kernel loads, completely bypassing kernel-mode security features including Hyper-V Code Integrity (HVCI), Endpoint Detection and Response (EDR) solutions, Windows Defender, and Hyper-V isolation. On systems using BitLocker with TPM-only protection, this attack vector enables [evil maid](https://en.wikipedia.org/wiki/Evil_maid_attack) attacks whereby VMK credentials can be captured during the pre-boot phase Boot Device Selection (BDS) phase. \r\n\r\n### Solution\r\n\r\nPlease see the Vendor Information section for patches provided by AOMEI International Network Limited to address this issue. CERT/CC recommends that AOMEI Backupper users update to a version that includes the corrected `amwrtdrv.sys` driver and implements appropriate access controls.\r\n\r\nUsers who cannot immediately apply the available update should consider uninstalling AOMEI Backupper. Alternatively, users may disable the `amwrtdrv.sys` service by changing its start type from `AUTO_START` to disabled. Enabling Secure Boot in UEFI firmware settings provides additional defense in depth by requiring signed bootloaders, but it does not address the underlying driver vulnerability.\r\n\r\n\r\n### Acknowledgements\r\nThank you to SiCk / afflicted.sh  for reporting this vulnerability. This document was written by Vijay Sarvepalli.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/687587"},{"url":"https://aomeitech.com","summary":"https://aomeitech.com"},{"url":"https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules","summary":"https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/microsoft-recommended-driver-block-rules"},{"url":"https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language","summary":"https://learn.microsoft.com/en-us/windows/win32/secauthz/security-descriptor-definition-language"}],"title":"AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks","tracking":{"current_release_date":"2026-09-10T17:46:33+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.45"}},"id":"VU#687587","initial_release_date":"2026-09-10 17:46:33.065329+00:00","revision_history":[{"date":"2026-09-10T17:46:33+00:00","number":"1.20260910174633.1","summary":"Released on 2026-09-10T17:46:33+00:00"}],"status":"final","version":"1.20260910174633.1"}},"vulnerabilities":[{"title":"AOMEI Backupper driver amwrtdrv.","notes":[{"category":"summary","text":"AOMEI Backupper driver amwrtdrv.sys local privilege escalation can lead to UEFI code execution"}],"ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#687587"}]}],"product_tree":{"branches":[{"category":"vendor","name":"Microsoft","product":{"name":"Microsoft Products","product_id":"CSAFPID-6c1de8ca-ae21-11f1-8ce3-12c4f731e8e5"}}]}}