CVE-2020-37254: Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37254?
The severity of CVE-2020-37254 is rated as high with a score of 8.5.
How do I fix CVE-2020-37254?
To fix CVE-2020-37254, ensure that the service path for WsAppService is correctly quoted to prevent privilege escalation.
What is CVE-2020-37254?
CVE-2020-37254 is a privilege escalation vulnerability in Wondershare PDFelement 5.2.9 caused by an unquoted service path.
Who is affected by CVE-2020-37254?
Local attackers with access to the system can exploit CVE-2020-37254 to escalate their privileges.
What action can a local attacker take in CVE-2020-37254?
A local attacker can place a malicious executable in the unquoted service path and execute it with LocalSystem privileges.