Macrium Reflect CVE-2020-10143 Arbitrary Code Execution Vulnerability

description-logoDescription

Macrium Reflect's privileged service uses an OpenSSL component with OPENSSLDIR set to C:\\\\openssl\\\\; because users can create subdirectories under the system root, they can place a crafted openssl.cnf to achieve arbitrary code execution with SYSTEM privileges.

affected-products-logoAffected Applications

Macrium Reflect

Version Updates

Date Version Status Detail
2025-07-03 1.00875
Modified
Macrium Reflect
2025-02-24 1.00822
Modified
Macrium Reflect
2021-12-29 1.00284
Modified
Macrium Reflect
2021-07-14 1.00253
New
Macrium Reflect