An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).
Metrics
Affected Vendors & Products
References
History
Thu, 22 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 22 May 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15). | |
Title | MSP360 Backup (for Windows) insecure filesystem permissions | |
Weaknesses | CWE-276 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: cisa-cg
Published: 2025-05-22T16:49:06.833Z
Updated: 2025-05-22T19:33:20.668Z
Reserved: 2025-04-16T17:28:05.083Z
Link: CVE-2025-43596

Updated: 2025-05-22T19:33:17.055Z

Status : Awaiting Analysis
Published: 2025-05-22T17:15:24.057
Modified: 2025-05-23T15:55:02.040
Link: CVE-2025-43596

No data.