9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-37021
Bandwidth Monitor General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

CVE-2020-37064
EPSON EasyMP Network Projection General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges.

CVE-2020-36974
Realtek Andrea RT Filters General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files\IDT\WDM\AESTSr64.exe' to inject malicious code that would execute during service startup or system reboot.

CVE-2020-36933
IPTInstaller General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges.

CVE-2020-37048
Iskysoft Application Framework Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the service's high-level system permissions.

CVE-2020-37062
DHCP Turbo General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service starts.

CVE-2020-37055
SpyHunter General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations to gain elevated access during service startup.

CVE-2020-36930
SysGauge General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGauge Server\bin\sysgaus.exe' to inject malicious executables and escalate privileges.

CVE-2020-37129
Memu Play General
8.5
HIGH
EPSS
0.0%
2020 CWE-276 1 PoC

Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.

CVE-2020-37063
TFTP Turbo General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.

CVE-2020-36916
TDM Digital Signage PC Player General
8.5
HIGH
EPSS
0.0%
2020 CWE-732 2 PoCs

TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access.

CVE-2020-36987
Program Access Controller General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.

CVE-2020-36976
Global Registration Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup.

CVE-2020-37061
BOOTP Turbo General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions.

CVE-2020-36983
Quick 'n Easy FTP Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code during service startup. Attackers can exploit the misconfigured service binary path to inject malicious executables with elevated LocalSystem privileges during system boot or service restart.

CVE-2020-36981
Motorola Device Manager General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 2 PoCs

Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in ForwardDaemon.exe to inject malicious code that will execute with elevated system privileges during service startup.

CVE-2020-36959
IDT PC Audio General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the STacSV service to inject malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2020-36991
ShareMouse General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

ShareMouse 5.0.43 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the insecure service path configuration by placing malicious executables in specific system directories to gain elevated access during service startup.

CVE-2020-37020
SonarQube General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.

CVE-2020-37059
Popcorn Time General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.