PT-2026-67676 · Asustor · Backup Plan+1
CVE-2026-18759
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ASUSTOR Backup Plan versions prior to 2.0.7.10172
ASUSTOR EZSync versions prior to 1.1.1.3114
Description
The background service runs as NT AUTHORITYSYSTEM and uses a file-based inter-process communication (IPC) mechanism protected by AES encryption. Since the encryption key file is readable by standard users and protected by DPAPI (Data Protection API), an authenticated local user can recover the key to forge valid IPC requests. Additionally, the service fails to verify the identity of the requesting process and employs an insufficient substring check for destination paths. This allows a local attacker to send crafted encrypted requests using directory traversal sequences to perform arbitrary file reads and writes with NT AUTHORITYSYSTEM privileges, resulting in full local privilege escalation.
Recommendations
Update ASUSTOR Backup Plan to a version later than 2.0.7.10171.
Update ASUSTOR EZSync to a version later than 1.1.1.3113.
Fix
LPE
Improper Privilege Management
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Backup Plan
Ezsync