PT-2026-26996 · Iperius · Iperius Backup

Bzyo

·

Published

2026-03-22

·

Updated

2026-03-22

·

CVE-2019-25608

CVSS v3.1

8.4

High

AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Iperius Backup 6.1.0 contains a privilege escalation vulnerability that allows low-privilege users to execute arbitrary programs with elevated privileges by creating backup jobs. Attackers can configure backup jobs to execute malicious batch files or programs before or after backup operations, which run with the privileges of the Iperius Backup Service account (Local System or Administrator), enabling privilege escalation and arbitrary code execution.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-25608

Affected Products

Iperius Backup