github.com
https://github.com/passtheticket/vulnerability-research/blob/main/privilege-escalation/pearsonvue-readme.md CVE-2020-36154
HIGH
Pearson Vue VTS 2.3.1911 Installer - VUEApplicationWrapper Unquoted Service Path
Record summary
CVE-2020-36154 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
The Application Wrapper in Pearson VUE VTS Installer 2.3.1911 has Full Control permissions for Everyone in the "%SYSTEMDRIVE%\Pearson VUE" directory, which allows local users to obtain administrative privileges via a Trojan horse application.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPearson Vue VTS 2.3.1911 Installer - VUEApplicationWrapper Unquoted Service PathExploitDB exploitby Jok3rNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36154 exploit-db.com
https://www.exploit-db.com/exploits/49143