VYPR

Cobian Backup

by Cocsoft

CVEs (2)

  • CVE-2017-11318HigJul 17, 2017
    risk 0.53cvss 8.1epss 0.01

    Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed. In addition, the attacker can execute system commands remotely by abusing pre-backup events.

  • CVE-2022-50923Jan 13, 2026
    risk 0.00cvss epss 0.00

    Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CobianReflectorService to inject malicious code that will execute with LocalSystem permissions during service startup.