CVE-2020-36981: Motorola Device Manager 2.4.5 - 'ForwardDaemon.exe ' Unquoted Service Path
Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in ForwardDaemon.exe to inject malicious code that will execute with elevated system privileges during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36981?
CVE-2020-36981 is considered a medium severity vulnerability due to its potential for local code execution.
How do I fix CVE-2020-36981?
To fix CVE-2020-36981, ensure that the service path for ForwardDaemon.exe is properly quoted and update to the latest version of Motorola Device Manager.
What type of vulnerability is CVE-2020-36981?
CVE-2020-36981 is an unquoted service path vulnerability that allows local users to execute arbitrary code.
Who is affected by CVE-2020-36981?
Users of Motorola Device Manager version 2.4.5 are affected by CVE-2020-36981.
Can CVE-2020-36981 be exploited remotely?
No, CVE-2020-36981 requires local access to the machine, making it a local privilege escalation vulnerability.