Impact
Duplicati v2.3.0.1 assigns MODIFY permissions to authenticated users that spread to all subdirectories. This is a CWE-732 weakness. As a result, installing the software outside the Program Files folder creates a LocalSystem service that runs from a directory writable by any standard local user, allowing a local attacker to replace a DLL in the service directory; when the service is restarted, Windows loads the attacker‑supplied DLL before executing the legitimate code, executing arbitrary code as SYSTEM.
Affected Systems
The impacted product is Duplicati backup software version 2.3.0.1, which is available for Windows operating systems. Users who installed the software on a non-default path or in a location with insufficient directory permissions are vulnerable. No other versions or operating systems were listed as affected.
Risk and Exploitability
The vulnerability is a high-severity privilege escalation, effectively giving a local attacker SYSTEM level execution. The existing EPSS score of < 1% indicates a very low exploitation probability, and the CVSS score of 7.8 confirms high severity. The vulnerability is not listed in CISA KEV, but the potential for arbitrary code execution still warrants immediate attention. The exploit requires only a standard local user account with write access to the installation directory and the ability to restart the service; no network component or elevated privileges are needed.
OpenCVE Enrichment