Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-36928. PoCs published by Brian Rodriguez.
AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in Brother BRAgent 1.38. The author provides steps to identify the vulnerability using WMIC and SC commands, highlighting the lack of quotes around the service path, which could allow local privilege escalation.
Description
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.
Exploits (1)
This is a technical writeup detailing an unquoted service path vulnerability in Brother BRAgent 1.38. The author provides steps to identify the vulnerability using WMIC and SC commands, highlighting the lack of quotes around the service path, which could allow local privilege escalation.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H