Neowin Microsoft Blocks Macrium Reflect Driver in Windows 11 Updates
Article Content
- •Microsoft's updates block the Macrium Reflect driver due to a known vulnerability.
- •Affected users cannot mount disk images, limiting backup functionality.
- •A temporary Registry hack workaround exists but increases security risks.
On May 2, 2026, Microsoft confirmed that its recent Windows 11 updates (KB5083769 and KB5083631) block the Macrium Reflect driver, psmounterex.sys, as part of its vulnerable driver blocklist. This action is a response to the discovery of a vulnerability (CVE-2023-43896) in versions 8.1.7544 and below of Macrium Reflect, which could allow attackers to execute arbitrary code. Users of Macrium Reflect are affected as the updates prevent the software from mounting or managing disk images, leading to backup failures. Microsoft has advised users to check their event logs for indications of the blocked driver and has not yet provided an official fix. Community discussions have surfaced a temporary workaround involving a Registry hack to disable the blocklist, although this poses security risks. Macrium's support team confirmed that only users of Version 8.1 are impacted, as newer versions do not utilize the blocked driver. The situation remains under investigation, with users advised to monitor for updates.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Macrium and CVE-2023-43896 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…