A null pointer dereference vulnerability exists in Macrium Reflect prior to version 8.1.8017. According to the provided information, a local attacker can trigger the flaw by executing a specially crafted executable, causing the vulnerable code path to dereference a null pointer. This can result in a system crash and may also create conditions for privilege escalation. Specific vulnerable functions or modules are not identified in the provided content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a local privilege escalation exploit for CVE-2024-55511, a null pointer dereference vulnerability in Macrium Reflect (prior to version 8.1.8017) on Windows. The exploit is implemented in C (CVE-2024-55511.c) and uses custom 64-bit shellcode (Shellcode.asm) to steal the SYSTEM token and assign it to the current process, effectively granting SYSTEM privileges. The exploit works by allocating the null page, placing pointers to the shellcode, and then triggering the vulnerability by opening and closing a handle to the vulnerable driver device (\\.\GLOBALROOT\Device\MRCBT). Upon successful exploitation, it spawns a SYSTEM-level command shell. The repository includes Visual Studio project files for building the exploit, and the code is operational, providing a working privilege escalation payload. No network or remote attack vectors are present; the exploit must be run locally on a vulnerable system.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.