---
id: CVE-2019-25608
title: Iperius Backup 6.1.0 Privilege Escalation via Backup Job
summary: >-
  Iperius Backup 6.1.0 contains a privilege escalation vulnerability that allows
  low-privilege users to execute arbitrary programs with elevated privileges by
  creating backup jobs. Attackers can configure backup jobs to execute malicious
  b…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-520
vendor: Iperius
product: Iperius Backup
affected:
  - backup 6.1.0
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-23T15:30:17.856616Z'
exploitAvailable: true
published: '2026-03-22'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:20.314Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2019-25608'
references:
  - url: 'https://www.exploit-db.com/exploits/46863'
    label: ExploitDB-46863
  - url: 'https://www.iperiusbackup.com/'
    label: Official Product Homepage
  - url: 'https://www.iperiusbackup.com/download.aspx'
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/iperius-backup-privilege-escalation-via-backup-job
    label: >-
      VulnCheck Advisory: Iperius Backup 6.1.0 Privilege Escalation via Backup
      Job
tags:
  - cve.org
  - exploit-available
epss: 0.00137
epssPercentile: 0.02568
ingestedAt: '2026-10-01T15:48:17.884Z'
---

## Overview

Iperius Backup 6.1.0 contains a privilege escalation vulnerability that allows low-privilege users to execute arbitrary programs with elevated privileges by creating backup jobs. Attackers can configure backup jobs to execute malicious batch files or programs before or after backup operations, which run with the privileges of the Iperius Backup Service account (Local System or Administrator), enabling privilege escalation and arbitrary code execution.

## Affected

- `backup 6.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
