CVE-2020-36977
HIGHWondershare Driver Install Service - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36977. PoCs published by Luis Sandoval.
AI-analyzed exploit summary This is a writeup describing an unquoted service path vulnerability in Wondershare Driver Install Service. The service path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation if an attacker can place a malicious executable in the path.
Description
Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to LocalSystem account.
Exploits (1)
This is a writeup describing an unquoted service path vulnerability in Wondershare Driver Install Service. The service path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation if an attacker can place a malicious executable in the path.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H