Impact
A flaw in the NTLM2 Handler component of Iperius Backup allows an attacker with local execution privileges to read sensitive information, potentially including credential data. The vulnerability falls under information disclosure (CWE-200) and unauthorized access to resources (CWE-284). Exploitation requires complex manipulation, so the attack is not trivial, but published exploits indicate it is feasible.
Affected Systems
The affected product is Enter Software Iperius Backup. Versions up to 8.7.3 are susceptible; the issue is fixed in version 8.7.4. The attack is limited to local execution and does not provide remote access.
Risk and Exploitability
The CVSS score of 2.0 classifies the severity as low. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Although the exploit requires local access and is difficult to execute, publicly disclosed proofs of concept exist, indicating that organisations running older versions could be exposed if local privilege is available. While the overall risk is low, applying the vendor‑issued fix is recommended to eliminate the disclosure path.
OpenCVE Enrichment