Macrium develops system backup and disaster-recovery software, with its Reflect product representing the core of its disclosed vulnerability surface and showing a pattern of memory-safety and access-control issues including classic buffer overflows, improper access control, and initialization defects. These are typical weaknesses for native-code backup utilities that operate with elevated privileges and parse diverse input formats; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Macrium over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43896HIGH A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code. | Oct 10, 2023 | 7.8 | 27 | NO | NO |
CVE-2020-10143HIGH Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. | Dec 9, 2020 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Macrium.
Media articles that mention a CVE ID that affects a product developed by Macrium — matched by CVE ID, not by vendor name.