216.73.217.22

CVE-2025-8070

· Published 23/07/2025 08:15 · Modified 23/07/2025 08:15

Labels: CVE-2025-8070 2025-07-23CVE-2025-8070CWE-428[email protected]

Essential information

Published
23/07/2025 08:15
Modified
23/07/2025 08:15
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces. Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
asustor / abp cpe:2.3:a:asustor:abp:2.0.7:*:*:*:*:*:*:*
asustor / aes cpe:2.3:a:asustor:aes:1.0.6:*:*:*:*:*:*:*

References