7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37064
EPSON EasyMP Network Projection General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges.

CVE-2020-37061
BOOTP Turbo General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions.

CVE-2020-36984
EPSON General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject malicious executables that will run with LocalSystem permissions.

CVE-2020-37055
SpyHunter General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations to gain elevated access during service startup.

CVE-2020-36975
Status Monitor 3 General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common Files\EPSON\EPW!3SSRP\E_S60RPB.EXE' to inject malicious executables and escalate privileges.

CVE-2020-37099
Disk Savvy Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Savvy Enterprise\bin\disksvs.exe' to inject malicious executables and escalate privileges.

CVE-2020-36974
Realtek Andrea RT Filters General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files\IDT\WDM\AESTSr64.exe' to inject malicious code that would execute during service startup or system reboot.

CVE-2020-37059
Popcorn Time General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.

CVE-2020-36959
IDT PC Audio General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the STacSV service to inject malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2020-36976
Global Registration Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup.

CVE-2020-37048
Iskysoft Application Framework Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the service's high-level system permissions.

CVE-2020-37017
CodeMeter General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CodeMeter Runtime Server service to inject malicious code that would execute with LocalSystem permissions.

CVE-2020-37102
Web Companion General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2020-37160
SprintWork Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-276 1 PoC

SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.

CVE-2020-37100
Sync Breeze Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process.

CVE-2020-37016
BarcodeOCR General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with elevated privileges during system startup. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will run with LocalSystem privileges.

CVE-2020-36987
Program Access Controller General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.

CVE-2020-37047
Deep Instinct Windows Agent Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepMgmtService.exe to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2020-36986
Prey General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Prey 1.9.6 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the CronService to insert malicious code that would execute during application startup or system reboot.

CVE-2020-37021
Bandwidth Monitor General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.