CVE-2025-13051

When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the service. Upon service restart, the malicious DLL is loaded and executed under the LocalSystem account, resulting in unauthorized code execution with elevated privileges. This issue affects ABP and AES: from ABP 2.0 through 2.0.7.9050, from AES 1.0 through 1.0.6.8290.
CVSS

No CVSS.

Configurations

No configuration.

History

19 Nov 2025, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 04:16

Updated : 2025-11-19 19:14


NVD link : CVE-2025-13051

Mitre link : CVE-2025-13051

CVE.ORG link : CVE-2025-13051


JSON object : View

Products Affected

No product.

CWE
CWE-427

Uncontrolled Search Path Element