An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute commands with root privileges in the 'Online Backup' folder. Upgrade to MSP360 Backup 4.4 (released on 2025-04-22).
References
Link | Resource |
---|---|
https://help.msp360.com/cloudberry-backup-mac-linux/whats-new | Release Notes |
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json | Third Party Advisory |
https://www.cve.org/CVERecord?id=CVE-2025-43595 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
23 Sep 2025, 15:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://help.msp360.com/cloudberry-backup-mac-linux/whats-new - Release Notes | |
References | () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-119-01.json - Third Party Advisory | |
References | () https://www.cve.org/CVERecord?id=CVE-2025-43595 - Third Party Advisory | |
First Time |
Msp360 backup
Linux Linux linux Kernel Msp360 |
|
CPE | cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:a:msp360:backup:4.3.1.115:*:*:*:*:*:*:* |
22 May 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-01 22:15
Updated : 2025-09-23 15:50
NVD link : CVE-2025-43595
Mitre link : CVE-2025-43595
CVE.ORG link : CVE-2025-43595
JSON object : View
Products Affected
msp360
- backup
linux
- linux_kernel
CWE
CWE-276
Incorrect Default Permissions