Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-36927. PoCs published by Brian Rodriguez.
AI-analyzed exploit summary This is a writeup detailing an unquoted service path vulnerability in DiskPulse 13.6.14. The vulnerability allows local privilege escalation due to improper handling of service paths containing spaces.
Description
DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse Enterprise\bin\diskpls.exe' to inject malicious executables and escalate privileges.
Exploits (1)
This is a writeup detailing an unquoted service path vulnerability in DiskPulse 13.6.14. The vulnerability allows local privilege escalation due to improper handling of service paths containing spaces.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H