9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-36984
EPSON General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject malicious executables that will run with LocalSystem permissions.

CVE-2020-37060
Atomic Alarm Clock x86 General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access.

CVE-2020-37030
Outline Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in C:\Program Files (x86)\Outline to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2020-36989
ForensiTAppxService General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2020-36952
IObit Uninstaller General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during service startup.

CVE-2020-26837
SAP Solution Manager (User Experience Monitoring) General
8.5
HIGH
EPSS
0.6%
2020 1 PoC

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise integrity allowing the modification of some configurations and partially compromise availability by making certain services unavailable.

CVE-2020-36977
Wondershare Driver Install Service help General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to LocalSystem account.

CVE-2016-20033
Wowza Streaming Engine General
8.5
HIGH
EPSS
0.0%
2016 CWE-639 2 PoCs

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart.

CVE-2016-20056
Spy Emergency General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.

CVE-2016-20061
sheed AntiVirus General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.

CVE-2016-20060
Hotspot Shield General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious code executes with LocalSystem privileges.

CVE-2016-20055
IObit Advanced SystemCare General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.

CVE-2016-15045
Deepin Linux General
8.5
HIGH
EPSS
1.4%
2016 CWE-306 3 PoCs

A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), the D-Bus configuration permits any user in the sudo group to invoke the InstallPackage method without password authentication. By default, the first user created on Deepin is in the sudo group. An attacker with shell access can craft a .deb package containing a malicious post-install script and use dbus-send to install it via lastore-daemon, resulting in arbit

CVE-2016-20057
NETGATE Registry Cleaner General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.

CVE-2016-20059
IObit Malware Fighter General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.

CVE-2016-20058
NETGATE AMITI Antivirus General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.

CVE-2018-25302
Allok AVI to DVD SVCD VCD Converter General
8.5
HIGH
EPSS
0.0%
2018 CWE-120 1 PoC

Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, SEH handler address, and shellcode that triggers the overflow when pasted into the License Name field and the Register button is clicked, resulting in code execution.

CVE-2018-25211
Splitter General
8.5
HIGH
EPSS
0.0%
2018 CWE-787 1 PoC

Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service or execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious payload exceeding 780 bytes, paste it into the License Name registration field, and trigger the overflow when the Register button is clicked.

CVE-2018-25154
GNU Barcode General
8.5
HIGH
EPSS
0.1%
2018 CWE-787 1 PoC

GNU Barcode 0.99 contains a buffer overflow vulnerability in its code 93 encoding process that allows attackers to trigger memory corruption. Attackers can exploit boundary errors during input file processing to potentially execute arbitrary code on the affected system.

CVE-2010-20107
FTP Synchronizer Professional General
8.5
HIGH
EPSS
23.1%
2010 CWE-121 2 PoCs

A stack-based buffer overflow exists in FTP Synchronizer Professional <= v4.0.73.274. When the client connects to an FTP server and issues a LIST command—typically during sync preview or profile creation—the server’s response containing an overly long filename triggers a buffer overflow. This results in the corruption of the Structured Exception Handler (SEH), potentially allowing remote code execution.