Impact
A known vulnerability exists in QILING Disk Master 6.0.0.0 within its kernel driver component diskbckp.sys. An unknown function in that driver permits local users to bypass normal access control, allowing the execution of code with kernel privileges. This flaw is a proper access-control weakness classified as CWE-266 and CWE-284. The main consequence is that a privileged local attacker can obtain full system control, potentially undermining the integrity and confidentiality of all data stored or processed by the affected machine.
Affected Systems
QILING Disk Master version 6.0.0.0, a disk backup and recovery application distributed with a kernel driver component. Any system running this exact version is affected; newer releases are not known to contain vulnerability resides in the kernel driver diskbckp.sys of QILING Disk Master 6.0.0.0, where improper access controls allow a local attacker to gain elevated privileges on the system. The weakness is classified under CWE-266 (Improper Privilege Management) and CWE-284 (Improper Access Control). It is inferred that an attacker who achieves kernel-level privileges can execute arbitrary code with full system control.
Risk and Exploitability
The CVSS score is 4.8, indicating moderate severity. EPSS is below 1%, and the vulnerability is not listed in the KEV catalog, implying low public exploitation probability. However, because the vector is local only, an attacker with local access can leverage the weakened driver to execute code with elevated kernel privileges, potentially leading to full system compromise. Limiting local user privileges and auditing driver usage will reduce the risk.
OpenCVE Enrichment