CVE-2025-61865: I-O Data Device, Inc Clone For Windows
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Multiple NAS management applications provided by I-O DATA DEVICE, INC. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
Affected products
- I-O Data Device, Inc Clone For Windows: before 2.36 (fixed in 2.36)
- I-O Data Device, Inc Narsus App: before 2.33 (fixed in 2.33)
Published 2025-10-23. Last modified 2026-06-17.