PT-2025-46789 · Nero · Nero Backitup
Published
2025-11-13
·
Updated
2025-11-14
·
CVE-2025-63680
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nero BackItUp versions 2019 through 2025
Description
Nero BackItUp contains a path parsing and user interface rendering flaw. This flaw, combined with how Windows handles file execution, can allow an attacker to run arbitrary code when a user clicks a specially crafted file. Specifically, creating a folder with a trailing dot and placing a script file with the same name inside causes Nero BackItUp to display the file as a folder. When the user clicks this “folder,” Windows attempts to execute the script file through a fallback mechanism. The vulnerable component is the way Nero BackItUp renders file names and interacts with the Windows
ShellExecuteW function.Recommendations
Versions prior to 2019 should be updated.
Versions 2019 through 2025 should be updated.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nero Backitup