We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-8070

Windows service registered with an unquoted ImagePath vulnerability in the system registry



Description

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces. Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.

Reserved 2025-07-23 | Published 2025-07-23 | Updated 2025-07-23 | Assigner ASUSTOR1


CRITICAL: 9.2CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:N/SA:N

Problem types

CWE-428 Unquoted Search Path or Element

Product status

Default status
unaffected

ABP 2.0
affected

AES 1.0
affected

Credits

Kazuma Matsumoto from GMO Cybersecurity by IERAE, Inc. finder

References

www.asustor.com/security/security_advisory_detail?id=47 vendor-advisory

cve.org (CVE-2025-8070)

nvd.nist.gov (CVE-2025-8070)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-8070

Support options

Helpdesk Chat, Email, Knowledgebase