CVE-2025-61865

Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
Configurations

No configuration.

History

10 Dec 2025, 07:15

Type Values Removed Values Added
References
  • () https://www.iodata.jp/support/information/2025/12_CloneforWindows/ -
Summary (en) NarSuS App registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. (en) Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

23 Oct 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-23 05:15

Updated : 2025-12-10 07:15


NVD link : CVE-2025-61865

Mitre link : CVE-2025-61865

CVE.ORG link : CVE-2025-61865


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element