Insecure Service Control Scripts in AudioCodes Fax Server and Auto-Attendant IVR Appliances
CVE-2025-34332
8.5HIGH
Key Information:
- Vendor
Audiocodes Limited
- Vendor
- CVE Published:
- 19 November 2025
What is CVE-2025-34332?
AudioCodes Fax Server and Auto-Attendant IVR appliances up to version 2.6.23 contain a significant vulnerability due to an insecure web administration component. This component allows authenticated local users to manipulate back-end Windows services through writable batch scripts, placed in a directory with overly permissive access control lists (ACLs). When the scripts are altered, they execute with NT AUTHORITY\SYSTEM privileges during service operations, giving attackers the ability to escalate their privileges locally.
Affected Version(s)
AudioCodes Fax/IVR Appliance 0 <= 2.6.23
