CVE-2018-25261 PUBLISHED

Iperius Backup 5.8.1 Local Buffer Overflow SEH

Assigner: VulnCheck
Reserved: 22.04.2026 Published: 22.04.2026 Updated: 22.04.2026

Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism that allows local attackers to execute arbitrary code by supplying a malicious file path. Attackers can create a backup job with a crafted payload in the external file location field that triggers a buffer overflow when the backup job executes, enabling code execution with application privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor Iperiusbackup
Product Iperius Backup
Versions Default: unaffected
  • Version 5.8.1 is affected

Credits

  • bzyo finder

References

Problem Types

  • Out-of-bounds Write CWE