Local Privilege Escalation Vulnerability in ASUSTOR Backup Plan and EZSync
CVE-2026-18759
What is CVE-2026-18759?
The ASUSTOR Backup Plan and EZSync products feature a background service that operates with elevated privileges due to using NT AUTHORITY\SYSTEM. This service employs a file-based inter-process communication (IPC) mechanism secured by AES encryption. However, the encryption key is accessible to standard users, enabling authenticated local users to extract the key and forge legitimate IPC requests. The service lacks sufficient authentication for the requesting processes and utilizes inadequate substring checks for destination paths. Consequently, a local attacker could leverage crafted encrypted requests with directory traversal sequences, permitting arbitrary file reads and writes as NT AUTHORITY\SYSTEM, resulting in full local privilege escalation risks.
Affected Version(s)
ABP and AES Windows ABP 2.0 <= 2.0.7.10171
ABP and AES Windows AES 1.0 <= 1.1.1.3113
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
