CVE-2020-36952: IObit Uninstaller 10 Pro - Unquoted Service Path
IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36952?
CVE-2020-36952 is classified as a medium severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2020-36952?
To fix CVE-2020-36952, ensure that the IObit Uninstaller 10 Pro service path is correctly quoted to prevent unauthorized code execution.
Who is affected by CVE-2020-36952?
Users of IObit Uninstaller 10 Pro are affected by CVE-2020-36952 due to the unquoted service path vulnerability.
What are the potential impacts of CVE-2020-36952?
The potential impacts of CVE-2020-36952 include the ability for attackers to execute arbitrary code with elevated privileges.
Is there a specific version of IObit Uninstaller that is vulnerable to CVE-2020-36952?
Yes, IObit Uninstaller 10 Pro is specifically vulnerable to CVE-2020-36952.