nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37253 CVE-2020-37253
HIGH
Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
Record summary
CVE-2020-37253 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WinstepBrowse Winstep / Winstep | CVE List | 18.06.0096 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWinstep 18.06.0096 - 'Xtreme Service' Unquoted Service PathExploitDB exploitby SamAlucardNot analyzed1 file
References
3ExploitDB-49004exploit
https://www.exploit-db.com/exploits/49004 VulnCheck Advisory: Winstep 18.06.0096 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/winstep-unquoted-service-path-privilege-escalation