CVE-2020-36992

HIGH

Nord VPN 6.31.13.0 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-36992. PoCs published by chipo.

AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in NordVPN's nordvpn-service. The vulnerability allows for potential privilege escalation due to the service path containing spaces and not being enclosed in quotes.

Description

Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions.

Exploits (1)

exploitdb WRITEUP
by chipo · textlocalwindows
https://www.exploit-db.com/exploits/48790

This is a technical writeup detailing an unquoted service path vulnerability in NordVPN's nordvpn-service. The vulnerability allows for potential privilege escalation due to the service path containing spaces and not being enclosed in quotes.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: NordVPN 6.31.13.0
Auth required
Prerequisites: Local access to the system · Ability to write to the Program Files directory
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/48790
Various Sources product
https://nordvpn.com

Scores

CVSS v3 7.8
EPSS 0.0016
EPSS Percentile 5.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
nordvpn/nordvpn 6.31.13.0
Published Jan 28, 2026
Tracked Since Feb 18, 2026