9.2
/ 10
CRITICAL
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:N/SA:N
Description
The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces.
Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.
Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.
Basic Information
ID
CVE-2025-8070
Source
ASUSTOR1
Published
Jul 23, 2025 at 07:26
Modified
Jul 23, 2025 at 14:10
Affected Product
Vendor
ASUSTOR
Product
ABP and AES
Version
ABP 2.0
Affected Versions
ASUSTOR ABP and AES ABP 2.0
ASUSTOR ABP and AES AES 1.0
ASUSTOR ABP and AES AES 1.0