Record summary

CVE-2020-37252 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.

Description

Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSystem privileges during service startup or system reboot.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0.0.55affected

Proofs of concept

1

Catalogued exploits

ExploitDBRealtek Audio Service 1.0.0.55 - 'RtkAudioService64.exe' Unquoted Service PathExploitDB exploitby Erika FigueroaNot analyzed1 file
ExploitDB

PoC details

References

4