CVE-2020-37253
HIGHWinstep 18.06.0096 Unquoted Service Path Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37253. PoCs published by SamAlucard.
AI-analyzed exploit summary This is a technical writeup demonstrating an unquoted service path vulnerability in Winstep Xtreme Service 18.06.0096. The output shows the service configuration, highlighting the unquoted path which could allow local privilege escalation if an executable is placed in the path.
Description
Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.
Exploits (1)
This is a technical writeup demonstrating an unquoted service path vulnerability in Winstep Xtreme Service 18.06.0096. The output shows the service configuration, highlighting the unquoted path which could allow local privilege escalation if an executable is placed in the path.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H