Product Referenceproduct
http://download.wondershare.com/inst/pdfelement_setup_full1042.exe CVE-2020-37254
HIGH
Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
Record summary
CVE-2020-37254 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PDFelementBrowse Wondershare / PDFelement | CVE List | 5.2.9 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWondershare PDFelement 5.2.9 - Unquoted Service Path Privilege EscalationExploitDB exploitby Saeed HasanzadehNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37254 ExploitDB-40535exploit
https://www.exploit-db.com/exploits/40535 VulnCheck Advisory: Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service PathThird-party advisory
https://www.vulncheck.com/advisories/wondershare-pdfelement-privilege-escalation-via-unquoted-service-path Official Product Homepageproduct
https://www.wondershare.com/