Local Buffer Overflow in Iperius Backup by Iperius
CVE-2018-25261
Key Information:
- Vendor
Iperiusbackup
- Status
- Vendor
- CVE Published:
- 22 April 2026
Badges
What is CVE-2018-25261?
Iperius Backup 5.8.1 features a local buffer overflow vulnerability in its structured exception handling (SEH) mechanism. This vulnerability allows local attackers to execute arbitrary code by providing a manipulated file path. By crafting a specific payload in the external file location field while creating a backup job, attackers can trigger a buffer overflow during the execution of that backup job, thereby enabling the execution of code with application privileges, which could potentially compromise the system’s security.
Affected Version(s)
Iperius Backup 5.8.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
