CVE-2020-36977

HIGH

Wondershare Driver Install Service - Privilege Escalation

Title source: llm
STIX 2.1

Description

Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to LocalSystem account.

Exploits (1)

exploitdb WRITEUP
by Luis Sandoval · textlocalwindows
https://www.exploit-db.com/exploits/49101

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Wondershare/Wondershare Driver Install Service help 10.7.1.321
Published Jan 27, 2026
Tracked Since Feb 18, 2026