PT-2025-18716 · Msp360 · Msp360 Backup

Published

2025-05-01

·

Updated

2025-05-02

·

CVE-2025-43595

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MSP360 Backup version 4.3.1.115
Description An insecure file system permissions vulnerability in MSP360 Backup allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder.
Recommendations Upgrade to MSP360 Backup 4.4 (released on 2025-04-22) to resolve the issue. As a temporary workaround, consider restricting access to the 'Online Backup' folder to minimize the risk of exploitation.

Fix

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-43595

Affected Products

Msp360 Backup