94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37020
SonarQube General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.

CVE-2020-37059
Popcorn Time General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.

CVE-2020-36984
EPSON General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject malicious executables that will run with LocalSystem permissions.

CVE-2020-37060
Atomic Alarm Clock x86 General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access.

CVE-2020-36990
Input Director Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Input Director 1.4.3 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.

CVE-2020-37030
Outline Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in C:\Program Files (x86)\Outline to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2020-36934
Deep Instinct Windows Agent Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Deep Instinct Windows Agent 1.2.24.0 contains an unquoted service path vulnerability in the DeepNetworkService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepNetworkService.exe to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2020-14880
BI Publisher (formerly XML Publisher) Web Database
8.5
HIGH
EPSS
0.3%
2020 1 PoC

Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. While the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, inse

CVE-2020-36989
ForensiTAppxService General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2020-36929
Brother BRPrint Auditor Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted file paths in BrAuSvc and BRPA_Agent services to inject malicious executables and escalate privileges on the system.

CVE-2020-36952
IObit Uninstaller General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during service startup.

CVE-2020-26837
SAP Solution Manager (User Experience Monitoring) General
8.5
HIGH
EPSS
0.6%
2020 1 PoC

SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious script that can exploit an existing path traversal vulnerability to compromise confidentiality exposing elements of the file system, partially compromise integrity allowing the modification of some configurations and partially compromise availability by making certain services unavailable.

CVE-2020-36977
Wondershare Driver Install Service help General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to LocalSystem account.

CVE-2016-20033
Wowza Streaming Engine General
8.5
HIGH
EPSS
0.0%
2016 CWE-639 2 PoCs

Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the nssm_x64.exe binary in the manager and engine service directories with malicious executables to execute code with LocalSystem privileges when services restart.

CVE-2016-20056
Spy Emergency General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.

CVE-2016-20061
sheed AntiVirus General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.

CVE-2016-20060
Hotspot Shield General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious code executes with LocalSystem privileges.

CVE-2016-20055
IObit Advanced SystemCare General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.

CVE-2016-15045
Deepin Linux General
8.5
HIGH
EPSS
1.4%
2016 CWE-306 3 PoCs

A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Linux (developed by Wuhan Deepin Technology Co., Ltd.). In versions 0.9.53-1 (Deepin 15.5) and 0.9.66-1 (Deepin 15.7), the D-Bus configuration permits any user in the sudo group to invoke the InstallPackage method without password authentication. By default, the first user created on Deepin is in the sudo group. An attacker with shell access can craft a .deb package containing a malicious post-install script and use dbus-send to install it via lastore-daemon, resulting in arbit

CVE-2016-20057
NETGATE Registry Cleaner General
8.5
HIGH
EPSS
0.0%
2016 CWE-428 1 PoC

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.