An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).
Metrics
Affected Vendors & Products
References
History
Thu, 22 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 May 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15). | |
| Title | MSP360 Backup (for Windows) insecure filesystem permissions | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-05-22T16:49:06.833Z
Updated: 2025-05-22T19:33:20.668Z
Reserved: 2025-04-16T17:28:05.083Z
Link: CVE-2025-43596
Updated: 2025-05-22T19:33:17.055Z
Status : Awaiting Analysis
Published: 2025-05-22T17:15:24.057
Modified: 2025-05-23T15:55:02.040
Link: CVE-2025-43596
No data.