Impact
The vulnerability resides in the configuration loader of Duplicati for Windows, which incorrectly assigns permissions to a critical resource. An attacker who has local low‑privileged access can place an attacker‑controlled preload.json file in the designated location. By doing so, the application will grant the file’s contents execution with elevated privileges, effectively allowing the attacker to gain SYSTEM level rights on the host. This raises the integrity and confidentiality of the system, as the attacker can modify or read any data and potentially compromise other services running on the machine.
Affected Systems
Duplicati for Windows versions earlier than 2.4.0.0 are affected. The vulnerability impacts the Duplicati application in its Windows build, and it requires the victim machine to be running a vulnerable version of this product. No other Duplicati products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 7 indicates high severity, but the EPSS score of less than 1% shows that the likelihood of exploitation is low at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting no known active exploitation. However, the attack vector is local, meaning an attacker must already have some level of local user access. If an attacker can create a preload.json file, privilege escalation to SYSTEM should be possible. The primary risk is the potential for an attacker to tamper with system configurations, install persistence mechanisms, or exfiltrate data once the SYSTEM privilege is achieved.
OpenCVE Enrichment