CVE-2025-43596

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
22/05/2025
Last modified:
23/09/2025

Description

An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:msp360:backup:*:*:*:*:*:*:*:* 8.0 (including) 8.1.1.19 (excluding)