CVE-2020-37016
HIGHBarcodeOCR 19.3.6 - Unquoted Service Path Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37016. PoCs published by Daniel Bertoni.
AI-analyzed exploit summary This writeup describes an unquoted service path vulnerability in BarcodeOCR 19.3.6, where the service path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation if an attacker can place a malicious executable in the path.
Description
BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with elevated privileges during system startup. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will run with LocalSystem privileges.
Exploits (1)
This writeup describes an unquoted service path vulnerability in BarcodeOCR 19.3.6, where the service path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation if an attacker can place a malicious executable in the path.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H