Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-9043 PoC — Seagate Toolkit 安全漏洞

Source
Associated Vulnerability
Title: Seagate Toolkit 安全漏洞 (CVE-2025-9043)
Description:The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Search Path or Element. An attacker with write permissions to the root could place a malicious Program.exe file, which would execute with SYSTEM privileges.
Readme
# CVE-2025-9043

## Description
An **Unquoted Search Path or Element** vulnerability (CWE-428) exists in **Seagate Toolkit** on Windows versions prior to **2.34.0.33**.  
The service executable path is not properly quoted, allowing an attacker with **administrative privileges** and **write access** to the root of the affected directory to place a malicious `Program.exe` file. When the vulnerable service is started, the malicious binary executes with **SYSTEM** privileges.

## Affected Product
- **Vendor:** Seagate Technology  
- **Product:** Seagate Toolkit  
- **Platform:** Windows  
- **Version:** Prior to 2.34.0.33  
- **Component:** Service executable path

## Vulnerability Details
- **Vulnerability Type:** Unquoted Search Path or Element (CWE-428)  
- **Attack Type:** Local 
- **Impact:**  
  - Escalation to SYSTEM privileges  
- **CVE ID:** [CVE-2025-9043](https://nvd.nist.gov/vuln/detail/CVE-2025-9043)  
- **CVSS Score (CNA):** 6.7 (Medium)  
- **CVSS Vector:** `CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N`

## Discoverer
Natthawut Saexu

## Proof of Concept (PoC)
The tester prepared a malicious DLL and a script to continuously copy it to the user-controlled path.
![PoC Screenshot](images/1.png)

The tester ran the installer and changed the installation path to a user-controllable location.
![PoC Screenshot](images/2.png)

After the installation completed, the tester gained a reverse shell back to the attack machine with SYSTEM privileges.
![PoC Screenshot](images/3.png)
![PoC Screenshot](images/4.png)

## References
- [NVD – CVE-2025-9043](https://nvd.nist.gov/vuln/detail/CVE-2025-9043)  
- [MITRE CVE Record](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-9043)  
- [Vendor Advisory – Seagate](https://www.seagate.com/product-security/#security-advisories)
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →