Executive brief
Nero BackItUp, a popular data backup and recovery application, contains a security flaw in how it displays files and folders within its built-in file browser. An attacker can trick the software into displaying a malicious script as if it were a harmless folder; if a user clicks this "folder," the script automatically runs on their computer. This could allow an attacker to gain full control over the user's system, access sensitive personal data, or compromise existing backups.
Technical details
Nero BackItUp is vulnerable to a path parsing and UI spoofing flaw (CWE-22) within its internal file browser. The application fails to properly normalize or filter Windows paths containing trailing dots (e.g., 'folder.'). When a directory with a trailing dot and a script file with a matching basename (e.g., 'folder..cmd') exist in the same location, the UI incorrectly renders the script file using a folder icon. Upon a user clicking this spoofed entry, the application invokes ShellExecuteW on the path. Due to Windows PATHEXT fallback resolution, the operating system executes the script (.COM, .EXE, .BAT, or .CMD) instead of opening a directory. This allows for arbitrary code execution in the context of the current user. The vulnerability affects Nero BackItUp versions from 2019 through 2025.
Affected products
- Nero BackItUp 2019 through 2025 and earlier
Timeline
- 2025-11-12: advisory: Researcher advisory published
- 2025-11-14: disclosed: CVE published