CVE 9.3 CRITICAL

Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem privileges_CVE-2025-13051

9.3 / 10
CRITICAL
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the service. Upon service restart, the malicious DLL is loaded and executed under the LocalSystem account, resulting in unauthorized code execution with elevated privileges.
This issue affects ABP and AES: from ABP 2.0 through 2.0.7.9050, from AES 1.0 through 1.0.6.8290.

AI Analysis

Uncontrolled search path element vulnerability allowing unauthorized code execution with elevated privileges

Basic Information

ID CVE-2025-13051
Source ASUSTOR1
Published Nov 19, 2025 at 02:50
Modified Nov 19, 2025 at 03:15

Affected Product

Vendor ASUSTOR
Product ABP and AES
Version ABP 2.0
Affected Versions ASUSTOR ABP and AES ABP 2.0
ASUSTOR ABP and AES AES 1.0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor ASUSTOR
Product ABP and AES
Version ABP 2.0 through 2.0.7.9050, AES 1.0 through 1.0.6.8290

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.