CVE-2020-36928

HIGH

Brother BRAgent 1.38 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-36928. PoCs published by Brian Rodriguez.

AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in Brother BRAgent 1.38. The author provides steps to identify the vulnerability using WMIC and SC commands, highlighting the lack of quotes around the service path, which could allow local privilege escalation.

Description

Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.

Exploits (1)

exploitdb WRITEUP
by Brian Rodriguez · textlocalwindows
https://www.exploit-db.com/exploits/50010

This is a technical writeup detailing an unquoted service path vulnerability in Brother BRAgent 1.38. The author provides steps to identify the vulnerability using WMIC and SC commands, highlighting the lack of quotes around the service path, which could allow local privilege escalation.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Brother BRAgent 1.38
Auth required
Prerequisites: Local access to the system · Ability to write to a directory in the unquoted service path
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0023
EPSS Percentile 13.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
brother/bragent 1.38
Published Jan 16, 2026
Tracked Since Feb 18, 2026