CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-8070

CVSS 9.2v4.0pub. 2025-07-23upd. 2026-04-15

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces. Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.

🤖 AI Analysis
How it works

The ImagePath registry value for Windows services ABP and AES is not enclosed in quotation marks, even though the path to the executable file contains spaces. When Windows attempts to interpret such a path, it checks shortened variants in sequence, allowing the attacker to place a malicious executable file in a predictable location, such as C:\Program.exe. When the service is started, Windows executes the planted file instead of the correct application file. If the service runs with elevated privileges, the attacker gains full control over the system at the SYSTEM level.

Impact

A local attacker can execute arbitrary code in the context of the service, and if the service has SYSTEM privileges, can gain full control over the operating system (privilege escalation to SYSTEM).

Mitigation & patch

ABP should be updated to a version higher than 2.0.7.6130 and AES to a version higher than 1.0.6.6133. Detailed information about available patches can be found in the manufacturer's security notice: https://www.asustor.com/security/security_advisory_detail?id=47

Who is affected

ABP version 2.0.7.6130 and earlier, and AES version 1.0.6.6133 and earlier running on Windows systems where the installation path contains spaces.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCELPE
CWE
References