CVE-2020-37253

HIGH

Winstep 18.06.0096 Unquoted Service Path Privilege Escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37253. PoCs published by SamAlucard.

AI-analyzed exploit summary This is a technical writeup demonstrating an unquoted service path vulnerability in Winstep Xtreme Service 18.06.0096. The output shows the service configuration, highlighting the unquoted path which could allow local privilege escalation if an executable is placed in the path.

Description

Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.

Exploits (1)

exploitdb WRITEUP
by SamAlucard · textlocalwindows
https://www.exploit-db.com/exploits/49004

This is a technical writeup demonstrating an unquoted service path vulnerability in Winstep Xtreme Service 18.06.0096. The output shows the service configuration, highlighting the unquoted path which could allow local privilege escalation if an executable is placed in the path.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Winstep Xtreme Service 18.06.0096
Auth required
Prerequisites: local access to the system · ability to place an executable in the unquoted path
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-49004
https://www.exploit-db.com/exploits/49004
Third Party Advisory third-party-advisory
VulnCheck Advisory: Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
https://www.vulncheck.com/advisories/winstep-unquoted-service-path-privilege-escalation

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 1.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Winstep/Winstep 18.06.0096
Published Jun 19, 2026
Tracked Since Jun 19, 2026