CVE-2025-34332
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-19

Last updated on: 2025-12-11

Assigner: VulnCheck

Description
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23Β include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain service actions are requested through ajaxPost.php, these scripts are invoked by PHP using system() under the NT AUTHORITY\\SYSTEM account. The batch files in this directory are writable by any authenticated local user due to overly permissive ACLs, allowing them to replace script contents with arbitrary commands. On the next service start/stop operation, the modified script is executed as SYSTEM, enabling elevation of local privileges.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-19
Last Modified
2025-12-11
Generated
2026-06-16
AI Q&A
2025-11-19
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
audiocodes fax_server to 2.6.23 (inc)
audiocodes interactive_voice_response to 2.6.23 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in AudioCodes Fax Server and Auto-Attendant IVR appliances up to version 2.6.23. The web administration component uses helper batch scripts to control Windows services, which are writable by any authenticated local user due to overly permissive access controls. An attacker can replace these scripts with arbitrary commands, which are then executed with SYSTEM privileges during service start/stop operations, allowing local privilege escalation.

Impact Analysis

An attacker with authenticated local access can exploit this vulnerability to execute arbitrary commands with SYSTEM-level privileges. This leads to elevation of local privileges, potentially allowing full control over the affected system, unauthorized access to sensitive data, and disruption of services.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-34332. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart