CVE-2020-10143 describes a privilege escalation vulnerability in Macrium Reflect, affecting versions that utilize a specific OpenSSL component. An unprivileged Windows user can exploit this by creating a malicious openssl.cnf file in a predictable path (C:\openssl\), leading to arbitrary code execution with SYSTEM privileges due to the privileged service using this component. Rated 7.8 HIGH on CVSS, this local attack requires low privileges and has high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.3.5281CPE matchmatch criteria | cpe:2.3:a:macrium:reflect:*:*:*:*:*:*:*:* | ||
>= 7.3, < 7.3.5281CPE match | cpe:2.3:a:macrium:reflect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.