CVE-2025-50892

7.8

EaseUs · Todo Backup

The eudskacs.sys driver in EaseUs Todo Backup fails to validate I/O request privileges, allowing local attackers to perform unauthorized raw disk operations.

Executive summary

A vulnerability in the EaseUs Todo Backup driver allows local, low-privileged attackers to achieve arbitrary disk access and potential privilege escalation.

Vulnerability

The eudskacs.sys driver improperly validates privileges for I/O control requests (IRP_MJ_READ and IRP_MJ_WRITE). This flaw allows a local, authenticated user to interact with the device object to conduct raw disk reads and writes.

Business impact

Successful exploitation of this vulnerability permits a local attacker to bypass operating system security controls to access sensitive data stored on raw disks. Furthermore, the ability to perform arbitrary disk writes can lead to a complete denial of service or the elevation of local privileges to administrative levels. With a CVSS score of 7.8, this vulnerability represents a high risk to the confidentiality, integrity, and availability of affected systems.

Remediation

Immediate Action: Restrict local access to systems running the affected version of EaseUs Todo Backup until a vendor-supplied patch is available.

Proactive Monitoring: Monitor system logs for unauthorized attempts to access or modify raw disk volumes and track unusual behavior originating from low-privileged user accounts.

Compensating Controls: Implement strict endpoint privilege management to ensure that only authorized users can execute commands or software on the host system.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists, attributed to the technical write-up referenced in the CVE record.

Analyst recommendation

Given the high CVSS severity and the existence of a public proof-of-concept, organizations should treat this vulnerability with urgency. Administrators must restrict access to the affected software and prioritize the application of security updates as soon as EaseUs releases a fix to prevent local privilege escalation.

More EaseUs CVEs

Sources