CVE-2020-37064: EPSON EasyMP Network Projection 2.81 - 'EMP_NSWLSV' Unquoted Service Path
EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMPNSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37064?
The severity of CVE-2020-37064 is considered moderate due to the potential for local code execution.
How do I fix CVE-2020-37064?
To fix CVE-2020-37064, modify the service path to be quoted properly in the Windows service settings.
Who is affected by CVE-2020-37064?
CVE-2020-37064 affects users of EPSON EasyMP Network Projection version 2.81.
What type of vulnerability is CVE-2020-37064?
CVE-2020-37064 is classified as an unquoted service path vulnerability.
Can CVE-2020-37064 be exploited remotely?
CVE-2020-37064 cannot be exploited remotely as it requires local access to the machine.