Impact
The vulnerability resides in the HID.dll library used by Softland’s FBackup Backup/Restore feature on Windows. By supplying a crafted link, a local attacker can trigger a path‑traversal flaw that causes the system to follow arbitrary paths. This allows a privileged user to read, modify, or execute files on the host, potentially leading to information disclosure or privilege escalation.
Affected Systems
Softland FBackup versions up to 9.9 on Windows installations are affected. The flaw is confined to the HID.dll component located in C:\Program Files\Common Files\microsoft shared\ink. No other products or versions are reported as vulnerable at this time.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, while the EPSS of less than 1% suggests a low probability of widespread exploitation in the short term. The flaw requires local access, so the risk is limited to users who can log on or run programs on the affected machine. It is not listed in the CISA KEV catalog, reducing its visibility in large‑scale threat feeds.
OpenCVE Enrichment