CVE-2018-25261 – Iperius Backup
“A long-standing weakness in backup software exposes critical data paths to real attack code.”
This patch addresses CVE-2018-25261 in Iperius Backup. The vulnerability affects backup operations, a core function responsible for safeguarding critical data. If exploited, it could allow attackers to interfere with backup integrity or gain unauthorized access to sensitive information. The CVSS score is 8.4, which is High severity, indicating a serious risk to business continuity and data protection.
Proof-of-concept code is available, confirming the vulnerability can be actively exploited. This raises the urgency, especially for environments relying on backups for recovery and resilience. The patch mitigates the issue and restores trust in backup operations.
Key Details
- Affected Product
- Entersrl Iperius Backup
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-787