CVE-2025-53394
Last modified
CVE-2025-53394 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed executable placed in the same directory. When a user with administrative privileges opens the crafted backup file and proceeds to mount it, Reflect launches the renamed executable (e.g., explorer.exe), which is under attacker control. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges via a crafted .mrimgx or .mrbax backup file and a renamed executable placed in the same directory. When a user with administrative privileges opens the crafted backup file and proceeds to mount it, Reflect launches the renamed executable (e.g., explorer.exe), which is under attacker control. This occurs because of insufficient validation of companion files referenced during backup mounting.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-53394?
How severe is CVE-2025-53394?
How do I fix CVE-2025-53394?
Are you affected by CVE-2025-53394?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
