CVE-2025-43596: MSP360 Backup

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands with SYSTEM level privileges using a specially crafted file with an arbitrary file backup target. Upgrade to MSP360 Backup 8.1.1.19 (released on 2025-05-15).

Affected products

  • MSP360 Backup: from 8.0, before 8.1.1.19 (fixed in 8.1.1.19)

Published 2025-05-22. Last modified 2026-06-17.