CNNVD-202512-4089 Information

CNNVD ID

CNNVD-202512-4089

CVE-2025-12838

  • CNNVD Published: 2025-12-23

Description (Chinese)

MSP360 Free Backup是MSP360公司的一个跨平台数据备份软件。 MSP360 Free Backup存在后置链接漏洞,该漏洞源于恢复功能存在链接跟随问题,可能导致本地权限提升。

Description (English)

MSP360 Free Backup is a cross-platform data backup software for MSP360. MSP360 Free Backup has a back-link loophole, which stems from the link-following problem of restoration, which may lead to an increase in local privileges.

Hazard Level

Medium

Vulnerability Type

后置链接

Affected Vendor

MSP360

Published

2025-12-23

Last Modified

2026-02-24

References

https://www.zerodayinitiative.com/advisories/ZDI-25-988/

Patch

https://www.msp360.com/backup/free-backup-software/

Share on: