CVE-2020-37254
HIGHWondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37254. PoCs published by Saeed Hasanzadeh.
AI-analyzed exploit summary This is a technical writeup describing an unquoted service path vulnerability in Wondershare PDFelement. The vulnerability allows local privilege escalation by exploiting the service's path to execute malicious code with elevated privileges.
Description
Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.
Exploits (1)
This is a technical writeup describing an unquoted service path vulnerability in Wondershare PDFelement. The vulnerability allows local privilege escalation by exploiting the service's path to execute malicious code with elevated privileges.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H