Web sayfamızı iyileştirmemize yardımcı olması için çerezler kullanırız. Lütfen Çerez Politikamızı okuyun.

AS-2025-008: ABP and AES

2025-07-23

Severity

Important

Status

Resolved


Statement

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as "C:\Program.exe". If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces.
Affected products and versions include: ABP (ASUSTOR Backup Plan) 2.0.7.6130 and earlier as well as AES (ASUSTOR EZSync) 1.0.6.6133 and earlier.

  • The issue has been fixed on ABP (ASUSTOR Backup Plan) 2.0.7.6131 and AES (ASUSTOR EZSync) 1.0.6.6134.

Affected Products

Product Severity Fixed Release Availability
ABP (ASUSTOR Backup Plan) Important Upgrade to ABP 2.0.7.6131 or above.
AES (ASUSTOR EZSync) Important Upgrade to AES 1.0.6.6134 or above.

Detail

  • CVE-2025-8070
    • Severity: Critical
    • CVSS4 Base Score: 9.2
    • CVSS4 Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:N/SA:N
    • The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as "C:\Program.exe". If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces. Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.

Acknowledgement

Kazuma Matsumoto from GMO Cybersecurity by IERAE, Inc.


Revision

Revision Date Description
1 2025-07-22 Initial public release.
2 2025-07-23 CVE ID (CVE-2025-8070) is assigned for the issue.
3 2025-07-23 ABP 2.0.7.6131 and AES 1.0.6.6134 has been released for fixing the issue.