CVE-2025-53395

7.7

Paramount · Macrium Reflect

Paramount Macrium Reflect is vulnerable to arbitrary code execution via a crafted .mrimgx backup file and a malicious DLL, triggered when an administrator mounts the file.

Executive summary

A local privilege escalation vulnerability in Macrium Reflect allows attackers with local access to execute arbitrary code with administrative privileges.

Vulnerability

The software suffers from an untrusted DLL search path flaw in ReflectMonitor.exe. An attacker can place a malicious VSSSvr.dll in the same directory as a crafted .mrimgx backup file to achieve code execution when an administrator mounts the backup.

Business impact

This vulnerability carries a high CVSS score of 7.7, reflecting the significant risk of full system compromise. If exploited, an attacker could gain administrative control over the affected machine, leading to total loss of confidentiality, integrity, and availability. Such a breach could result in unauthorized access to sensitive backup data and potential lateral movement within the network.

Remediation

Immediate Action: Update Macrium Reflect to the latest version provided by the vendor to resolve the DLL search path vulnerability.

Proactive Monitoring: Monitor system logs for unexpected file access or process execution originating from the directory where backup files are stored.

Compensating Controls: Restrict local write permissions to directories where backup files are maintained to prevent unauthorized placement of malicious DLL files.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete administrative compromise, organizations using Macrium Reflect must prioritize patching. Identify all systems running versions of the software released on or before June 26, 2025, and apply the vendor-supplied updates immediately to mitigate this risk.

Sources