← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 10, 2026 · 17:46via CERT/CC Vulnerability Notes

VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks

Brief

Overview

An incorrect permissions assignment vulnerability in the amwrtdrv. sys kernel driver, included with AOMEI Backupper 8.

  • 0, allows an unprivileged local user to perform arbitrary writes to the physical disk. When Secure Boot is disabled, this can be leveraged to execute arbitrary UEFI-level code before the operating system loads.

This allows an attacker to bypass OS-level security controls, including HVCI, EDR solutions, and Microsoft Defender. The attack may also enable capture of BitLocker Volume Master Key (VMK) material, depending on the system's BitLocker configuration.

Description

AOMEI Backupper from AOMEI International Network Limited is designed to provide backup and disaster recovery services. It also helps individuals and businesses to create system images, disk clones, and file backups.

Read more on CERT/CC Vulnerability Notes→