CVE-2018-25261: Entersrl Iperius Backup
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism that allows local attackers to execute arbitrary code by supplying a malicious file path. Attackers can create a backup job with a crafted payload in the external file location field that triggers a buffer overflow when the backup job executes, enabling code execution with application privileges.
Affected products
- Entersrl Iperius Backup: version 5.8.1 only
Published 2026-04-22. Last modified 2026-06-17.