Jens

Jens Beimel

0

Article
Last Month

Vulnerability Disclosure Policy

Published July 17th, 2026 by Jens Beimel

Purpose and Security Objective Matrix42 is committed to the responsible, transparent, and coordinated handling of security vulnerabilities. This Vulnerability Disclosure Policy describes the public reporting channel for security researchers, customers, partners, and other third parties, as well as the internal handling of incoming vulnerability repo

414 Views 5 min

CVE-2026-57919: Privilege Escalation in Matrix42 Empirum Personal Backup via Insecure Named Pipe Permissions and Untrusted Search Path

Published June 26th, 2026 by Jens Beimel

Summary PBackupVSS.exe in Matrix42 Empirum creates a named pipe (\\\\.\\pipe\\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages to trigger execution of arbitrary commands with SYSTEM privileges via an untrus

1143 Views 1 min
Load More