---
id: CVE-2025-66461
title: FULLBACK Manager Pro provided by GS Yuasa International Ltd
summary: >-
  FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers  two
  Windows services with unquoted file paths. A user may execute arbitrary code
  with SYSTEM privilege if he/she has the write permission on the path to the
  director…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
published: '2025-12-08'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66461'
references:
  - url: 'https://jvn.jp/en/jp/JVN59242986/'
    label: vultures@jpcert.or.jp
  - url: >-
      https://ps.gs-yuasa.com/technicalinfo/pdf/failure/FMP_info20251201_TEX48214-993.pdf
    label: vultures@jpcert.or.jp
tags:
  - nvd
epss: 0.00155
epssPercentile: 0.04013
ingestedAt: '2026-10-07T20:46:46.762Z'
---

## Overview

FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers  two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM privilege if he/she has the write permission on the path to the directory where the affected product is installed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
