CVE-2020-37101
HIGHVPN Unlimited 6.1 - Unquoted Service Path Privilege Escalation via Service Binary Path Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37101. PoCs published by Amin Rawah.
AI-analyzed exploit summary This exploit demonstrates an unquoted service path vulnerability in VPN Unlimited 6.1, where the service binary path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation via path manipulation.
Description
VPN Unlimited 6.1 contains an unquoted service path vulnerability that allows local attackers to inject malicious executables into the service binary path. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\VPN Unlimited\' to replace the service executable and gain elevated system privileges.
Exploits (1)
This exploit demonstrates an unquoted service path vulnerability in VPN Unlimited 6.1, where the service binary path contains spaces and is not enclosed in quotes, potentially allowing local privilege escalation via path manipulation.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H