CVE-2025-50892
7.8EaseUs · Todo Backup
The eudskacs.sys driver in EaseUs Todo Backup fails to validate I/O request privileges, allowing local attackers to perform unauthorized raw disk operations.
Executive summary
A vulnerability in the EaseUs Todo Backup driver allows local, low-privileged attackers to achieve arbitrary disk access and potential privilege escalation.
Vulnerability
The eudskacs.sys driver improperly validates privileges for I/O control requests (IRP_MJ_READ and IRP_MJ_WRITE). This flaw allows a local, authenticated user to interact with the device object to conduct raw disk reads and writes.
Business impact
Successful exploitation of this vulnerability permits a local attacker to bypass operating system security controls to access sensitive data stored on raw disks. Furthermore, the ability to perform arbitrary disk writes can lead to a complete denial of service or the elevation of local privileges to administrative levels. With a CVSS score of 7.8, this vulnerability represents a high risk to the confidentiality, integrity, and availability of affected systems.
Remediation
Immediate Action: Restrict local access to systems running the affected version of EaseUs Todo Backup until a vendor-supplied patch is available.
Proactive Monitoring: Monitor system logs for unauthorized attempts to access or modify raw disk volumes and track unusual behavior originating from low-privileged user accounts.
Compensating Controls: Implement strict endpoint privilege management to ensure that only authorized users can execute commands or software on the host system.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists, attributed to the technical write-up referenced in the CVE record.
Analyst recommendation
Given the high CVSS severity and the existence of a public proof-of-concept, organizations should treat this vulnerability with urgency. Administrators must restrict access to the affected software and prioritize the application of security updates as soon as EaseUs releases a fix to prevent local privilege escalation.