Record summary

CVE-2020-37253 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.

Description

Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List18.06.0096affected

Proofs of concept

1

Catalogued exploits

ExploitDBWinstep 18.06.0096 - 'Xtreme Service' Unquoted Service PathExploitDB exploitby SamAlucardNot analyzed1 file
ExploitDB

PoC details

References

3