Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-36992. PoCs published by chipo.
AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in NordVPN's nordvpn-service. The vulnerability allows for potential privilege escalation due to the service path containing spaces and not being enclosed in quotes.
Description
Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions.
Exploits (1)
This is a technical writeup detailing an unquoted service path vulnerability in NordVPN's nordvpn-service. The vulnerability allows for potential privilege escalation due to the service path containing spaces and not being enclosed in quotes.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H