Insecure Service Control Scripts in AudioCodes Fax Server and Auto-Attendant IVR Appliances
CVE-2025-34332
Key Information:
- Vendor
Audiocodes Limited
- Vendor
- CVE Published:
- 19 November 2025
Badges
What is CVE-2025-34332?
AudioCodes Fax Server and Auto-Attendant IVR appliances up to version 2.6.23 contain a significant vulnerability due to an insecure web administration component. This component allows authenticated local users to manipulate back-end Windows services through writable batch scripts, placed in a directory with overly permissive access control lists (ACLs). When the scripts are altered, they execute with NT AUTHORITY\SYSTEM privileges during service operations, giving attackers the ability to escalate their privileges locally.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AudioCodes Fax/IVR Appliance 0 <= 2.6.23
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
