CVE-2020-36983

HIGH

Quick 'n Easy FTP Service 3.2 - RCE

Title source: llm
STIX 2.1

Description

Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code during service startup. Attackers can exploit the misconfigured service binary path to inject malicious executables with elevated LocalSystem privileges during system boot or service restart.

Exploits (1)

exploitdb WRITEUP
by yunaranyancat · textlocalwindows
https://www.exploit-db.com/exploits/48983

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Pablosoftwaresolutions/Quick 'n Easy FTP Service 3.2
Published Jan 27, 2026
Tracked Since Feb 18, 2026