Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37058. PoCs published by Roberto Piña.
AI-analyzed exploit summary This is a writeup detailing an unquoted service path vulnerability in Andrea ST Filters Service 1.0.64.7. The vulnerability allows local privilege escalation if an attacker can place an executable in a path that the service attempts to run due to improper quoting.
Description
Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup.
Exploits (1)
This is a writeup detailing an unquoted service path vulnerability in Andrea ST Filters Service 1.0.64.7. The vulnerability allows local privilege escalation if an attacker can place an executable in a path that the service attempts to run due to improper quoting.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H