CVE-2023-43896Patch(macrium / reflect)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch macrium reflect systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • reflect

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-05-04); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
reflect

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 105-0405-0505-06
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • ALI OSUL@ALIOSSOL1
    Patch

    🚨 هشدار فنی: مایکروسافت تایید کرد آپدیت امنیتی اپریل2026 با افزودن درایور psmounterex.sys به Blocklist (برای مقابله با اکسپلویت CVE-2023-43896)، باعث اختلال در VSS Snapshot و شکست عملیات Mount در نرم‌ افزار های بک‌ آپ شده است. راه حل Patch کردن نرم‌ افزار به آخرین نسخه است https://t.co/27GsDQYNkm

    Post summary

    Microsoft announced an April 2026 security update that blocks the driver psmounterex.sys to mitigate CVE-2023-43896, causing disruptions in VSS Snapshot and backup software, and recommends applying the latest patch.

    0005096
    877 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    ⚠️ وش سبب الحظر؟ الدرايفر (psmounterex.sys) مرتبط بثغرة عالية الخطورة رقمها (CVE-2023-43896). الثغرة هذي تسمح للمخترق برفع صلاحياته أو تنفيذ كود عشوائي بالنظام، وعشان كذا مايكروسوفت أضافته لقائمة الحظر (Vulnerable Driver Blocklist) في التحديث الأخير.

    Post summary

    The post reports that Microsoft has blocked driver psmounterex.sys due to CVE‑2023‑43896, which permits privilege escalation or arbitrary code execution, as part of a recent update.

    10000473
    49.0K followersView on X
  • CinchOps@CinchOpsIT
    Patch

    💾 𝗔𝗽𝗿𝗶𝗹 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 𝗨𝗽𝗱𝗮𝘁𝗲 𝗶𝘀 𝗤𝘂𝗶𝗲𝘁𝗹𝘆 𝗕𝗿𝗲𝗮𝗸𝗶𝗻𝗴 𝗕𝗮𝗰𝗸𝘂𝗽𝘀 Microsoft blocked psmounterex.sys to fix CVE-2023-43896. Macrium Reflect, Acronis, NinjaOne Backup, and UrBackup all break on image mounts. Backups may look like they're running while doing nothing. You'll find out when you need a restore, the worst possible moment. ❓ When did you last test a restore, not just a backup? 📲 CinchOps can audit your backup chain end-to-end. 🌐 http://cinchops.com/contact | 📲 281-269-6506 Full Article: https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-backup-failures-caused-by-vulnerable-driver-block/ #ITSupport #cybersecurity #HoustonSMB #DataBackup #DisasterRecovery

    Post summary

    Microsoft's April Windows update blocks the vulnerable psmounterex.sys driver, fixing CVE-2023-43896 and resolving backup failures across several backup solutions.

    0000081
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmacriumreflect8.1.7544--

Explore more