Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37129. PoCs published by chuyreds.
AI-analyzed exploit summary This exploit demonstrates a local privilege escalation vulnerability in Memu Play 7.1.3 due to insecure folder permissions. A low-privilege user can replace the MemuService.exe with a malicious executable, which executes with SYSTEM privileges upon reboot.
Description
Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting unrestricted file modification permissions.
Exploits (1)
This exploit demonstrates a local privilege escalation vulnerability in Memu Play 7.1.3 due to insecure folder permissions. A low-privilege user can replace the MemuService.exe with a malicious executable, which executes with SYSTEM privileges upon reboot.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H