Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37060. PoCs published by boku.
AI-analyzed exploit summary This exploit leverages an unquoted service path vulnerability in Atomic Alarm Clock 6.3 to escalate privileges from Admin to SYSTEM. By placing a malicious 'Program.exe' in the root drive, an attacker can achieve arbitrary code execution with SYSTEM privileges.
Description
Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access.
Exploits (1)
This exploit leverages an unquoted service path vulnerability in Atomic Alarm Clock 6.3 to escalate privileges from Admin to SYSTEM. By placing a malicious 'Program.exe' in the root drive, an attacker can achieve arbitrary code execution with SYSTEM privileges.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H