CVE-2025-9043 Details
Description
The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Search Path or Element. An attacker with write permissions to the root could place a malicious Program.exe file, which would execute with SYSTEM privileges.
A vulnerability allowing unquoted search path exploitation has been identified in Seagate Toolkit versions prior to 2.34.0.33 for Windows. This issue arises from the service executable path, which can be manipulated by an attacker with admin privileges. If the attacker has write permissions to the root directory, they could place a malicious 'Program.exe' file that would execute with SYSTEM privileges.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 14, 2025CISA-ADP
Assessed Aug 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.seagate.com/product-security/#security-advisories | Seagate Technology | |
| https://www.seagate.com/support/software/toolkit/ | Seagate Technology | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | Seagate Technology |
Affected Products
| Product | Versions |
|---|---|
| Seagate Toolkit | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Seagate Technology |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 21, 2025 | CVE Modified | CVE |
| Aug 21, 2025 | CVE Modified | Seagate Technology |
| Aug 15, 2025 | CVE Modified | CVE |
| Aug 14, 2025 | New CVE Received | Seagate Technology |
Volerion