CVE-2020-36937: MEMU PLAY 3.7.0 - 'MEmusvc' Unquoted Service Path
Microvirt MEMU Play 3.7.0 contains an unquoted service path vulnerability in the MEmusvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with elevated LocalSystem privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36937?
CVE-2020-36937 has a medium severity rating due to its potential to allow local attackers to execute arbitrary code.
How do I fix CVE-2020-36937?
To fix CVE-2020-36937, ensure that the service paths are correctly quoted in the Windows service configuration.
What is the impact of CVE-2020-36937?
The impact of CVE-2020-36937 is that local attackers may exploit the unquoted service path vulnerability to inject and execute malicious code.
What versions are affected by CVE-2020-36937?
CVE-2020-36937 specifically affects the Microvirt MEMU Play version 3.7.0.
Who can exploit CVE-2020-36937?
CVE-2020-36937 can be exploited by local attackers who have access to the vulnerable system.