CVE-2025-66461 MEDIUM

CVE-2025-66461

Vendor Gs Yuasa International Ltd.
Product FULLBACK Manager Pro (for Windows)
Weakness CWE-428
Published December 8, 2025
Last update December 8, 2025

CVSS base score

6.7/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM privilege if he/she has the write permission on the path to the directory where the affected product is installed.

Key dates

02Disclosure timeline

December 8, 2025 CVE published
December 8, 2025 Record updated