When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the service. Upon service restart, the malicious DLL is loaded and executed under the LocalSystem account, resulting in unauthorized code execution with elevated privileges.
This issue affects ABP and AES: from ABP 2.0 through 2.0.7.9050, from AES 1.0 through 1.0.6.8290.
CVSS
No CVSS.
References
Configurations
No configuration.
History
19 Nov 2025, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 04:16
Updated : 2025-11-19 19:14
NVD link : CVE-2025-13051
Mitre link : CVE-2025-13051
CVE.ORG link : CVE-2025-13051
JSON object : View
Products Affected
No product.
CWE
CWE-427
Uncontrolled Search Path Element
