CVE-2025-8070 - CVE House
Back to Database
Status published Critical CVE-2025-8070

Windows service registered with an unquoted ImagePath vulnerability in the system registry

Vulnerability Description

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execute arbitrary code by placing a malicious executable in a predictable location such as C:\Program.exe. If the service runs with elevated privileges, exploitation results in privilege escalation to SYSTEM level. This vulnerability arises from an unquoted service path affecting systems where the executable resides in a path containing spaces. Affected products and versions include: ABP 2.0.7.6130 and earlier as well as AES 1.0.6.6133 and earlier.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8070

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Kazuma Matsumoto from GMO Cybersecurity by IERAE, Inc.

Affected Vendor

Affected Software

ABP and AES
Vulnerable Versions:
ABP 2.0, AES 1.0

Timeline

Official Publish: July 23rd, 2025
Last Modified: July 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)