Description

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces. Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.

INFO

Published Date :

2025-07-23T07:26:03.531Z

Last Modified :

2025-07-23T14:10:47.430Z

Source :

ASUSTOR1
AFFECTED PRODUCTS

The following products are affected by CVE-2025-8070 vulnerability.

Vendors Products
Asustor
  • Abp
  • Aes
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-8070.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability