CVE-2023-43896
A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code.
CVSS
7.8
High
EPSS
0.3%
p28
KEV
—
Exploit Today
8
0-100
Published: Oct 10, 2023 · Last modified: Jul 9, 2026 · CWE-120
0.3%EPSS · 30 days0.3%
2026-08-182026-09-15
A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code.
- knowledgebase.macrium.comhttps://knowledgebase.macrium.com/display/KNOW80/CVE-2023-43896+Advisory
- northwave-cybersecurity.comhttps://northwave-cybersecurity.com/vulnerability-notice/macrium-reflect-driver-out-of-bounds-write
- knowledgebase.macrium.comhttps://knowledgebase.macrium.com/display/KNOW80/CVE-2023-43896+Advisory
- northwave-cybersecurity.comhttps://northwave-cybersecurity.com/vulnerability-notice/macrium-reflect-driver-out-of-bounds-write
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-920438.8 HIG—
——0Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.14hCVE-2026-920208.8 HIG—
——0Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.14hCVE-2026-920148.8 HIG—
——0Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.14hCVE-2026-920138.8 HIG—
——0Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.14hCVE-2026-920128.8 HIG—
——0Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.14hCVE-2026-920118.8 HIG—
——0Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.14h