CVE-2025-13051 - CVE House
Back to Database
Status published Critical CVE-2025-13051

Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem privileges

Vulnerability Description

When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replace or plant a DLL with the same name as one loaded by the service. Upon service restart, the malicious DLL is loaded and executed under the LocalSystem account, resulting in unauthorized code execution with elevated privileges. This issue affects ABP and AES: from ABP 2.0 through 2.0.7.9050, from AES 1.0 through 1.0.6.8290.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13051

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Kazuma Matsumoto, Security Researcher at GMO Cybersecurity by IERAE, Inc.

Affected Vendor

Affected Software

ABP and AES
Vulnerable Versions:
ABP 2.0, AES 1.0

Timeline

Official Publish: November 19th, 2025
Last Modified: November 19th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)