CVE-2018-25261 – Iperius Backup

CVSS 8.4 IMPORTANT

“A long-standing weakness in backup software exposes critical data paths to real attack code.”

This patch addresses CVE-2018-25261 in Iperius Backup. The vulnerability affects backup operations, a core function responsible for safeguarding critical data. If exploited, it could allow attackers to interfere with backup integrity or gain unauthorized access to sensitive information. The CVSS score is 8.4, which is High severity, indicating a serious risk to business continuity and data protection.

Proof-of-concept code is available, confirming the vulnerability can be actively exploited. This raises the urgency, especially for environments relying on backups for recovery and resilience. The patch mitigates the issue and restores trust in backup operations.

Key Details

Affected Product
Entersrl Iperius Backup
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-787
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.