HomeSecurityASUSTOR: Critical vulnerability allows malicious code execution

ASUSTOR: Critical vulnerability allows malicious code execution

A new, particularly serious vulnerability in ASUSTOR has been uncovered by the cybersecurity community, revealing that two of the company’s core applications could allow attackers to run malicious code with elevated privileges. The vulnerability has been documented as CVE-2025-13051 and is classified as high risk, especially for users who continue to rely on older versions of the applications.

ASUSTOR

ASUSTOR was quick to release patch updates, but the damage this vulnerability can cause is significant.

Where the gap comes from: DLL hijacking

This is a DLL hijacking vulnerability that occurs when the ASUSTOR Backup Plan (ABP) and ASUSTOR EZSync (AES) services are installed in directories accessible by non-administrative users.

See also: Grafana: Critical vulnerability allows privilege escalation

The technique is well-known: the attacker replaces a genuine DLL used by the application with a modified, malicious version. Since the new file has the same name as the legitimate DLL, the service loads it without a second thought.

The result? Upon restart, the application executes the malicious code as LocalSystem, the most powerful privilege level in a Windows environment.

Attacker capabilities: From full access to permanent backdoor installation

Executing code with LocalSystem privileges is not just a technical error; it is a path to complete computer domination.

See also: Broadcom: Cl0p breach via zero-day in Oracle EBS?

An attacker who exploits the vulnerability could:

  • install ransomware or spyware,
  • modify critical security settings,
  • intercept sensitive data from connected shares,
  • create persistent access even if the user reboots,
  • move across the entire network, especially when ASUSTOR tools are present on business computers.

The DLL hijacking technique has been known for years, but it remains particularly effective when used on services running at high privilege levels — and backup tools are just that.

ASUSTOR: Critical vulnerability allows malicious code execution

ASUSTOR: Which versions are affected?

ASUSTOR confirmed that the vulnerability affects:

  • ABP version 2.0.7.9050 and older,
  • AES version 1.0.6.8290 and older.

Although the tools are not superficially considered “high risk,” many systems have had them installed for years without frequent updates. As a result, many users remain vulnerable without knowing it.

Available Updates – What Users Should Do Immediately

ASUSTOR released patches a few days after the vulnerability was disclosed:

  • ABP 2.0.7.10171 or later,
  • AES 1.1.0.10312 or later.

Users are urged to upgrade immediately, as the vulnerability is easily exploitable and does not require advanced attack techniques.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Fortinet: 'Silent' patch for second zero-day vulnerability

ASUSTOR: Critical vulnerability allows malicious code execution

What it means for the backup application ecosystem

Synchronization and backup solutions are often silent but critical links in a network's security. Organizations emphasize storage platforms and NAS, but overlook client-side tools, which act as a bridge between the endpoint and the server.

If such a tool is compromised:

  • can act as an entry point for attacks,
  • is an ideal vehicle for lateral movement,
  • can become a “mirror” of the user's data for the attacker.

This is why experts emphasize that backup tools should be treated with the same seriousness as antivirus or identity platforms.

ASUSTOR acted quickly, but the onus now shifts to users, who must immediately install available updates and review their backup installation and management practices.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS