Local Privilege Escalation Vulnerability in ASUSTOR Backup Plan and EZSync
CVE-2026-18759

8.5HIGH

Key Information:

Vendor
CVE Published:
4 August 2026

What is CVE-2026-18759?

The ASUSTOR Backup Plan and EZSync products feature a background service that operates with elevated privileges due to using NT AUTHORITY\SYSTEM. This service employs a file-based inter-process communication (IPC) mechanism secured by AES encryption. However, the encryption key is accessible to standard users, enabling authenticated local users to extract the key and forge legitimate IPC requests. The service lacks sufficient authentication for the requesting processes and utilizes inadequate substring checks for destination paths. Consequently, a local attacker could leverage crafted encrypted requests with directory traversal sequences, permitting arbitrary file reads and writes as NT AUTHORITY\SYSTEM, resulting in full local privilege escalation risks.

Affected Version(s)

ABP and AES Windows ABP 2.0 <= 2.0.7.10171

ABP and AES Windows AES 1.0 <= 1.1.1.3113

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kazuma Matsumoto, Security Researcher at GMO Cybersecurity by IERAE, Inc.
.