CVE Database
/

CVE-2025-8070

Back to search

CVE-2025-8070

Published: Jul 23, 2025

Modified: Jul 23, 2025

PUBLISHED

Description

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces. Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.

VendorProductVersions

ASUSTOR

ABP and AES

affected
ABP 2.0 - <= 2.0.7.6130
affected
AES 1.0 - <= 1.0.6.6133

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now