ZeroHour

CVE-2026-76159

moderate

Local Privilege Escalation to SYSTEM via preload. in Duplicati for Windows

CVSS 4.0
7.0 high
EPSS
Published
()
Modified
AI analysis

Duplicati for Windows versions before v2.4.0.0 suffer from an incorrect permission assignment (CWE-732) on a critical resource used by its configuration loader, which runs in the context of the highly privileged Duplicati service. A local attacker with only low-privileged access can plant an attacker-controlled preload. file that the loader picks up, causing attacker-supplied configuration (and effectively code execution) to run as NT AUTHORITY\SYSTEM. Exploitation requires prior local access and some user interaction, but yields full system-level compromise of the affected machine. Anyone running Duplicati on Windows prior to v2.4.0.0 is affected, with the greatest risk on multi-user systems where untrusted local accounts exist. No public proof of concept is known, the flaw is not in CISA's KEV catalog, and there is no evidence of in-the-wild exploitation at this time.

What to do: Upgrade Duplicati for Windows to v2.4.0.0 or later as soon as possible. In the interim, tighten NTFS permissions on the Duplicati configuration directory so low-privileged users cannot write preload., and audit existing installs for unexpected or recently modified preload. files. Restrict local account creation on hosts running the Duplicati service, since the flaw requires local low-privileged access to exploit.

Affected
Duplicati for Windowsbefore v2.4.0.0
Estimated exposure
moderateon the order of tens of thousands of Windows installations (rough estimate, ~10k-100k) — Duplicati is a popular free, open-source backup client with years of widespread downloads but no official active-install telemetry, so this is an order-of-magnitude guess; the practical impact is further limited to machines with untrusted…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.

Weakness
CWE-732
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.