CVE-2025-43595

An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).
Configurations

No configuration.

History

22 May 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de permisos del sistema de archivos inseguro en MSP360 Backup 4.3.1.115 permite que un usuario con pocos privilegios ejecute comandos con privilegios de root en la carpeta "Copia de seguridad en línea". Actualice a MSP360 Backup 4.4 (publicada el 22/04/2025).
References
  • () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json -
  • () https://www.cve.org/CVERecord?id=CVE-2025-43595 -

02 May 2025, 03:15

Type Values Removed Values Added
Summary (en) An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a lower privileged user to execute commands with root level privileges in the 'Online Backup' folder. Users are recommended to upgrade to MSP360 Backup 4.4 (released on 2025-04-22). (en) An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).

01 May 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-01 22:15

Updated : 2025-05-22 17:15


NVD link : CVE-2025-43595

Mitre link : CVE-2025-43595

CVE.ORG link : CVE-2025-43595


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions