CVE-2025-9043
The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Search Path or Element. An attacker with write permissions to the root could place a malicious Program.exe file, which would execute with SYSTEM privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9043?
CVE-2025-9043 is classified as a high severity vulnerability due to the potential for privilege escalation.
How do I fix CVE-2025-9043?
To fix CVE-2025-9043, upgrade to Seagate Toolkit version 2.34.0.33 or later.
What is the attack vector for CVE-2025-9043?
CVE-2025-9043 can be exploited by attackers with admin privileges who have write access to the root directory.
What type of vulnerability is CVE-2025-9043?
CVE-2025-9043 is categorized as an unquoted search path vulnerability, specifically under CWE-428.
Which versions of Seagate Toolkit are affected by CVE-2025-9043?
Seagate Toolkit versions prior to 2.34.0.33 are affected by CVE-2025-9043.