CVE-2020-37254

HIGH

Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37254. PoCs published by Saeed Hasanzadeh.

AI-analyzed exploit summary This is a technical writeup describing an unquoted service path vulnerability in Wondershare PDFelement. The vulnerability allows local privilege escalation by exploiting the service's path to execute malicious code with elevated privileges.

Description

Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.

Exploits (1)

exploitdb WRITEUP
by Saeed Hasanzadeh · textlocalwindows
https://www.exploit-db.com/exploits/40535

This is a technical writeup describing an unquoted service path vulnerability in Wondershare PDFelement. The vulnerability allows local privilege escalation by exploiting the service's path to execute malicious code with elevated privileges.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Wondershare PDFelement 5.2.9
Auth required
Prerequisites: Local access to the system · Ability to place an executable in the service path
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-40535
https://www.exploit-db.com/exploits/40535
Product product
Official Product Homepage
https://www.wondershare.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
https://www.vulncheck.com/advisories/wondershare-pdfelement-privilege-escalation-via-unquoted-service-path

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
Wondershare/PDFelement 5.2.9
Published Jun 19, 2026
Tracked Since Jun 19, 2026