Description

Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallback extension resolution, leads to arbitrary code execution when a user clicks a crafted entry. By creating a trailing-dot folder and placing a same-basename script, Nero BackItUp renders the file as a folder icon and then invokes ShellExecuteW, which executes the script via PATHEXT fallback (.COM/.EXE/.BAT/.CMD). The issue affects recent Nero BackItUp product lines (2019-2025 and earlier) and has been acknowledged by the vendor.

INFO

Published Date :

2025-11-14T00:00:00.000Z

Last Modified :

2025-11-14T19:21:27.874Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-63680 vulnerability.

Vendors Products
Microsoft
  • Windows
Nero
  • Backitup
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-63680.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact