9.3
/ 10
CRITICAL
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the service. Upon service restart, the malicious DLL is loaded and executed under the LocalSystem account, resulting in unauthorized code execution with elevated privileges.
This issue affects ABP and AES: from ABP 2.0 through 2.0.7.9050, from AES 1.0 through 1.0.6.8290.
This issue affects ABP and AES: from ABP 2.0 through 2.0.7.9050, from AES 1.0 through 1.0.6.8290.
AI Analysis
Uncontrolled search path element vulnerability allowing unauthorized code execution with elevated privileges
Basic Information
ID
CVE-2025-13051
Source
ASUSTOR1
Published
Nov 19, 2025 at 02:50
Modified
Nov 19, 2025 at 03:15
Affected Product
Vendor
ASUSTOR
Product
ABP and AES
Version
ABP 2.0
Affected Versions
ASUSTOR ABP and AES ABP 2.0
ASUSTOR ABP and AES AES 1.0
ASUSTOR ABP and AES AES 1.0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
ASUSTOR
Product
ABP and AES
Version
ABP 2.0 through 2.0.7.9050, AES 1.0 through 1.0.6.8290