CVE-2020-36982: Motorola Device Manager 2.5.4 - 'MotoHelperService.exe' Unquoted Service Path
Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperService.exe service that allows local users to potentially inject malicious code. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with elevated system privileges during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36982?
CVE-2020-36982 is classified as a medium severity vulnerability due to its potential for local code injection.
How do I fix CVE-2020-36982?
To fix CVE-2020-36982, ensure that the service path for MotoHelperService.exe is properly quoted to mitigate the risk of local code execution.
Who is affected by CVE-2020-36982?
CVE-2020-36982 affects users of Motorola Device Manager version 2.5.4 that have installed the MotoHelperService.exe.
What type of vulnerability is CVE-2020-36982?
CVE-2020-36982 is an unquoted service path vulnerability that can be exploited to execute arbitrary code.
Can CVE-2020-36982 be exploited remotely?
No, CVE-2020-36982 requires local access for exploitation, limiting its potential impact to users with physical or administrative access to the affected system.