Description
Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism that allows local attackers to execute arbitrary code by supplying a malicious file path. Attackers can create a backup job with a crafted payload in the external file location field that triggers a buffer overflow when the backup job executes, enabling code execution with application privileges.
Problem types
Product status
5.8.1 (semver)
Credits
bzyo
References
www.exploit-db.com/exploits/46059 (ExploitDB-46059)
www.iperiusbackup.com (Official Product Homepage)
www.vulncheck.com/...perius-backup-local-buffer-overflow-seh (VulnCheck Advisory: Iperius Backup 5.8.1 Local Buffer Overflow SEH)