Impact
The vulnerability arises from improper privilege management in the Backup Job Configuration File Handler component of Iperius Backup. Manipulation of this handler enables a local attacker to obtain elevated privileges within the application, potentially leading to unauthorized control over backup operations and sensitive data. The weakness is associated with CWE-266 and CWE-269, indicating flawed privileged access management.
Affected Systems
Enter Software Iperius Backup versions up to and including 8.7.3 are affected. Users running these releases should verify the exact build and consider applying the update to 8.7.4 as released by the vendor.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high severity, and the attack requires local access with high complexity, making exploitation nontrivial. Although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the combination of high severity and confirmed public disclosure suggests that organizations should treat it as a significant risk pending patch deployment.
OpenCVE Enrichment