ABP and AES
An improper authentication and path traversal vulnerability exists in ASUSTOR Backup Plan (ABP) and ASUSTOR EZ Sync (AES). A local attacker can submit crafted encrypted requests containing directory traversal sequences to perform arbitrary file reads and arbitrary file writes as NT AUTHORITY\SYSTEM, leading to full local privilege escalation.
Affected products and versions include: ABP (ASUSTOR Backup Plan) 2.0.7.10171 and earlier as well as AES (ASUSTOR EZSync) 1.1.1.3113 and earlier.
- The issue has been fixed on AES (ASUSTOR EZSync) 1.1.1.7230.
- The issue has been fixed on ABP (ASUSTOR Backup Plan) 2.0.8.7230.