I-O DATA NarSuS App Unquoted Service Path Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in the I-O DATA NarSuS App due to the registration of a Windows service with an unquoted file path. This flaw allows users with write permissions on the root directory of the system drive to execute arbitrary code with SYSTEM privileges. The vulnerability affects NarSuS App versions prior to 2.33.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with SYSTEM privileges.

Remediation

Users are advised to update the NarSuS App to version 2.33 or later. The latest version can be downloaded from the I-O DATA website.

Added: Oct 23, 2025, 5:21 AM
Updated: Oct 23, 2025, 5:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.