CyberRota Analysis
AI-GeneratedA vulnerability in the configuration loader of Duplicati for Windows versions prior to 2.4.0.0 allows local low-privileged attackers to escalate their privileges to NT AUTHORITY\SYSTEM by manipulating a preload.json file. This high-severity flaw poses a significant risk to systems running affected versions, making it critical for organizations using Duplicati to prioritize upgrading to the latest version to mitigate potential exploitation.
Original NVD Description
Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.