MSP360 Backup Insecure Filesystem Permissions Vulnerability Allowing Elevated Privileges
Vulnerability
A vulnerability exists in MSP360 Backup versions 8.0 for Windows and 4.3.1.115 for Linux, where insecure file system permissions allow low privileged users to execute commands with elevated privileges. In the Windows version, this could lead to executing commands with SYSTEM privileges, while in the Linux version, commands could be executed with root privileges. The vulnerability can be exploited by using a specially crafted file directed to an arbitrary backup target.
Impact
Exploitation of this vulnerability allows for unauthorized command execution with elevated privileges, potentially leading to administrative access and manipulation of system settings or data.
Remediation
Users are advised to upgrade to MSP360 Backup 8.1.1.19 for Windows or MSP360 Backup 4.4 for Linux.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
