CVE-2025-13051
When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the service. Upon service restart, the malicious DLL is loaded and executed under the LocalSystem account, resulting in unauthorized code execution with elevated privileges. This issue affects ABP and AES: from ABP 2.0 through 2.0.7.9050, from AES 1.0 through 1.0.6.8290.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.19%
- CWE
- CWE-427
- Published
- 2025-11-19
- Last modified
- 2026-03-13
Affected products
- ASUSTOR ABP and AES
- ASUSTOR ABP and AES
Weakness type
Related vulnerabilities
- CVE-2019-25268 — NREL BEopt 2.8.0 Insecure Library Loading Arbitrary Code Execution
- CVE-2025-65118 — AVEVA Process Optimization Uncontrolled Search Path Element
- CVE-2026-87530 — Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a l
- CVE-2025-30248 — DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker t
- CVE-2026-29610 — OpenClaw < 2026.2.14 - Command Hijacking via Unsafe PATH Handling
- CVE-2026-24502 — Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit
- CVE-2025-33208 — NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.
- CVE-2026-28456 — OpenClaw 2026.1.5 < 2026.2.14 - Arbitrary Code Execution via Unsafe Hook Module Path Handling