Insecure Service Control Scripts in AudioCodes Fax Server and Auto-Attendant IVR Appliances
CVE-2025-34332

8.5HIGH

What is CVE-2025-34332?

AudioCodes Fax Server and Auto-Attendant IVR appliances up to version 2.6.23 contain a significant vulnerability due to an insecure web administration component. This component allows authenticated local users to manipulate back-end Windows services through writable batch scripts, placed in a directory with overly permissive access control lists (ACLs). When the scripts are altered, they execute with NT AUTHORITY\SYSTEM privileges during service operations, giving attackers the ability to escalate their privileges locally.

Affected Version(s)

AudioCodes Fax/IVR Appliance 0 <= 2.6.23

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.
CVE-2025-34332 : Insecure Service Control Scripts in AudioCodes Fax Server and Auto-Attendant IVR Appliances