Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-36937. PoCs published by SamAlucard.
AI-analyzed exploit summary This is a technical writeup demonstrating an unquoted service path vulnerability in MEMU PLAY 3.7.0. The exploit leverages the lack of quotes around the service path to potentially execute arbitrary code with elevated privileges.
Description
Microvirt MEMU Play 3.7.0 contains an unquoted service path vulnerability in the MEmusvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with elevated LocalSystem privileges.
Exploits (1)
This is a technical writeup demonstrating an unquoted service path vulnerability in MEMU PLAY 3.7.0. The exploit leverages the lack of quotes around the service path to potentially execute arbitrary code with elevated privileges.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H