CVE-2020-36987
HIGHProgram Access Controller 1.2.0.0 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36987. PoCs published by Mohammed Alshehri.
AI-analyzed exploit summary This exploit describes an unquoted service path vulnerability in Program Access Controller v1.2.0.0, which could allow local privilege escalation by exploiting the service path to execute arbitrary code with elevated privileges during system startup or reboot.
Description
Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.
Exploits (1)
This exploit describes an unquoted service path vulnerability in Program Access Controller v1.2.0.0, which could allow local privilege escalation by exploiting the service path to execute arbitrary code with elevated privileges during system startup or reboot.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H