CVE-2025-66461
CVE-2025-66461
FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM privilege if he/she has the write permission on the path to the directory where the affected product is installed.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
GS Yuasa International Ltd. · FULLBACK Manager Pro for Network (for Windows)GS Yuasa International Ltd. · FULLBACK Manager Pro (for Windows)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →