94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-36982
Motorola Device Manager General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperService.exe service that allows local users to potentially inject malicious code. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with elevated system privileges during service startup.

CVE-2020-36953
MiniTool ShadowMaker General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject malicious executables and escalate privileges.

CVE-2020-37160
SprintWork Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-276 1 PoC

SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.

CVE-2020-37102
Web Companion General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2020-36957
PDF Complete General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.

CVE-2020-36879
DiskBoss General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.

CVE-2020-36992
nordvpn Networking
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions.

CVE-2020-36985
IP Watcher Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

IP Watcher 3.0.0.30 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated LocalSystem privileges during service startup.

CVE-2020-37098
Disk Sorter Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.

CVE-2020-37016
BarcodeOCR General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with elevated privileges during system startup. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will run with LocalSystem privileges.

CVE-2020-37100
Sync Breeze Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process.

CVE-2020-37021
Bandwidth Monitor General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

CVE-2020-37064
EPSON EasyMP Network Projection General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges.

CVE-2020-36974
Realtek Andrea RT Filters General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files\IDT\WDM\AESTSr64.exe' to inject malicious code that would execute during service startup or system reboot.

CVE-2020-36927
DiskPulse Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse Enterprise\bin\diskpls.exe' to inject malicious executables and escalate privileges.

CVE-2020-36958
Kite Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious executables and escalate privileges on the system.

CVE-2020-2863
Advanced Outbound Telephony Web Database
8.5
HIGH
EPSS
0.5%
2020 1 PoC

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. While the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessib

CVE-2020-36933
IPTInstaller General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges.

CVE-2020-37048
Iskysoft Application Framework Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the service's high-level system permissions.

CVE-2020-37062
DHCP Turbo General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service starts.