<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Unquoted Service Path (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/service-path.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/service-path-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Unquoted Service Path (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:45 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2021-47974 – VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Sea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47974</guid>
    <pubDate>Sat, 16 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47974</strong></p>
  <p>VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories like C:\Program Files\VX Search to execute arbitrary code with LocalSystem privileges when services restart.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37247 – Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteServi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37247</guid>
    <pubDate>Sat, 16 May 2026 16:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37247</strong></p>
  <p>Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37232 – Advanced System Care Service 13.0.0.157 contains an unquoted service path vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37232</guid>
    <pubDate>Sat, 16 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37232</strong></p>
  <p>Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Attackers can place malicious executables in the system root path that will be executed with LocalSystem privileges during service startup or system reboot.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37231 – Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37231</guid>
    <pubDate>Sat, 16 May 2026 16:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37231</strong></p>
  <p>Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Attackers can place malicious executables in the unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system reboot.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37230 – Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37230</guid>
    <pubDate>Sat, 16 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37230</strong></p>
  <p>Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path. Attackers can insert a malicious executable into the service path and execute it with LocalSystem privileges when the service restarts or the system reboots.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37229 – OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37229</guid>
    <pubDate>Sat, 16 May 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37229</strong></p>
  <p>OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unquoted path. Attackers can place a malicious executable in a directory within the service path that will execute with LocalSystem privileges when the service restarts or the system reboots.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37223 – IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37223</guid>
    <pubDate>Wed, 13 May 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37223</strong></p>
  <p>IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to execute code with SYSTEM privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47945 – Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47945</guid>
    <pubDate>Sun, 10 May 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47945</strong></p>
  <p>Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the Program Files directory to be executed with LocalSystem privileges when the service starts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-20061 – sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20061</guid>
    <pubDate>Sat, 04 Apr 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-20061</strong></p>
  <p>sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-20060 – Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20060</guid>
    <pubDate>Sat, 04 Apr 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-20060</strong></p>
  <p>Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious code executes with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-20059 – IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20059</guid>
    <pubDate>Sat, 04 Apr 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-20059</strong></p>
  <p>IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-20058 – Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20058</guid>
    <pubDate>Sat, 04 Apr 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-20058</strong></p>
  <p>Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-20057 – NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20057</guid>
    <pubDate>Sat, 04 Apr 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-20057</strong></p>
  <p>NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-20056 – Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20056</guid>
    <pubDate>Sat, 04 Apr 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-20056</strong></p>
  <p>Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-20055 – IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-20055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-20055</guid>
    <pubDate>Sat, 04 Apr 2026 14:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-20055</strong></p>
  <p>IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-20055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41359 – Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41359</guid>
    <pubDate>Thu, 26 Mar 2026 13:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41359</strong></p>
  <p>Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploit…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25345 – Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25345</guid>
    <pubDate>Thu, 12 Feb 2026 20:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25345</strong></p>
  <p>Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service configuration to inject malicious executables and escalate privileges on the system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25310 – ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25310</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25310</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25310</strong></p>
  <p>ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated administrative privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25310">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25309 – Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25309</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25309</strong></p>
  <p>Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25308 – Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikog...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25308</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25308</strong></p>
  <p>Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific path locations.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25307 – WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25307</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25307</strong></p>
  <p>WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25306 – BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25306</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25306</strong></p>
  <p>BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25305 – JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25305</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25305</guid>
    <pubDate>Fri, 06 Feb 2026 17:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25305</strong></p>
  <p>JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25305">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25304 – SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25304</guid>
    <pubDate>Fri, 06 Feb 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25304</strong></p>
  <p>SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\ISS\SecurOS\ to insert malicious code that would execute with system-level permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25302 – Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25302</guid>
    <pubDate>Fri, 06 Feb 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25302</strong></p>
  <p>Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to insert malicious code that would execute with system-level permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25293 – BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25293</guid>
    <pubDate>Fri, 06 Feb 2026 17:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25293</strong></p>
  <p>BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25292 – Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25292</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25292</guid>
    <pubDate>Fri, 06 Feb 2026 17:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25292</strong></p>
  <p>Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\Apoint2K\HidMonitorSvc.exe to inject malicious executables and gain system-level access.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25292">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25266 – Wondershare Application Framework Service 2.4.3.231 contains an unquoted service...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25266</guid>
    <pubDate>Fri, 06 Feb 2026 17:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25266</strong></p>
  <p>Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific directory locations to hijack the service's execution context.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25288 – Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25288</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25288</strong></p>
  <p>Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute malicious code with elevated privileges. Attackers can insert an executable file in the service path to run unauthorized code when the service restarts or the system reboots.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25287 – Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25287</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25287</strong></p>
  <p>Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious code that would execute with LocalSystem privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25286 – GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25286</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25286</strong></p>
  <p>GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25285 – Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25285</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25285</strong></p>
  <p>Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the system reboots.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25283 – Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25283</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25283</strong></p>
  <p>Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25281 – NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25281</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25281</strong></p>
  <p>NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted paths in services like ncprwsnt, rwsrsu, ncpclcfg, and NcpSec to inject malicious code that would execute with LocalSystem privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25276 – Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25276</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25276</strong></p>
  <p>Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject malicious code that would execute with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25275 – BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNServ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25275</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25275</strong></p>
  <p>BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service's execution context.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25274 – ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25274</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25274</strong></p>
  <p>ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25273 – Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the Easy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25273</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25273</strong></p>
  <p>Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Easy-Hide-IP\rdr\EasyRedirect.exe' to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25272 – TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25272</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25272</strong></p>
  <p>TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious executables and gain elevated system privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25271 – NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25271</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25271</strong></p>
  <p>NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25269 – Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25269</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25269</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25269</strong></p>
  <p>Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges by placing executable files in specific directory locations.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25269">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25267 – Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25267</guid>
    <pubDate>Thu, 05 Feb 2026 00:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25267</strong></p>
  <p>Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37102 – Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37102</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37102</strong></p>
  <p>Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37101 – VPN Unlimited 6.1 contains an unquoted service path vulnerability that allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37101</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37101</strong></p>
  <p>VPN Unlimited 6.1 contains an unquoted service path vulnerability that allows local attackers to inject malicious executables into the service binary path. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\VPN Unlimited\' to replace the service executable and gain elevated system privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37100 – Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37100</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37100</strong></p>
  <p>Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37099 – Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37099</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37099</strong></p>
  <p>Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Savvy Enterprise\bin\disksvs.exe' to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37098 – Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37098</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37098</strong></p>
  <p>Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25261 – AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25261</guid>
    <pubDate>Tue, 03 Feb 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25261</strong></p>
  <p>AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37064 – EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37064</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37064</strong></p>
  <p>EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37063 – TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37063</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37063</strong></p>
  <p>TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37062 – DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37062</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37062</strong></p>
  <p>DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service starts.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37061 – BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37061</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37061</strong></p>
  <p>BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37055 – SpyHunter 4 contains an unquoted service path vulnerability that allows local us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37055</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37055</strong></p>
  <p>SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations to gain elevated access during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37048 – Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37048</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37048</strong></p>
  <p>Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the service's high-level system permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37047 – Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37047</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37047</strong></p>
  <p>Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepMgmtService.exe to inject malicious code that would execute with LocalSystem permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37045 – Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the Net...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37045</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37045</strong></p>
  <p>Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37037 – Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37037</guid>
    <pubDate>Sun, 01 Feb 2026 15:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37037</strong></p>
  <p>Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37060 – Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in it...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37060</guid>
    <pubDate>Fri, 30 Jan 2026 17:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37060</strong></p>
  <p>Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37059 – Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37059</guid>
    <pubDate>Fri, 30 Jan 2026 17:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37059</strong></p>
  <p>Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37058 – Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37058</guid>
    <pubDate>Fri, 30 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37058</strong></p>
  <p>Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37030 – Outline Service 1.3.3 contains an unquoted service path vulnerability that allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37030</guid>
    <pubDate>Fri, 30 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37030</strong></p>
  <p>Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in C:\Program Files (x86)\Outline to inject malicious code that would execute with LocalSystem permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37021 – 10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37021</guid>
    <pubDate>Thu, 29 Jan 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37021</strong></p>
  <p>10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37020 – SonarQube 8.3.1 contains an unquoted service path vulnerability that allows loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37020</guid>
    <pubDate>Thu, 29 Jan 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37020</strong></p>
  <p>SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37017 – CodeMeter 6.60 contains an unquoted service path vulnerability that allows local...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37017</guid>
    <pubDate>Thu, 29 Jan 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37017</strong></p>
  <p>CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CodeMeter Runtime Server service to inject malicious code that would execute with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-37016 – BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37016</guid>
    <pubDate>Thu, 29 Jan 2026 15:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-37016</strong></p>
  <p>BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with elevated privileges during system startup. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will run with LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36992 – Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36992</guid>
    <pubDate>Wed, 28 Jan 2026 13:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36992</strong></p>
  <p>Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36991 – ShareMouse 5.0.43 contains an unquoted service path vulnerability that allows lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36991</guid>
    <pubDate>Wed, 28 Jan 2026 13:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36991</strong></p>
  <p>ShareMouse 5.0.43 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the insecure service path configuration by placing malicious executables in specific system directories to gain elevated access during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36990 – Input Director 1.4.3 contains an unquoted service path vulnerability in its Wind...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36990</guid>
    <pubDate>Wed, 28 Jan 2026 13:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36990</strong></p>
  <p>Input Director 1.4.3 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36989 – ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36989</guid>
    <pubDate>Wed, 28 Jan 2026 13:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36989</strong></p>
  <p>ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36987 – Program Access Controller 1.2.0.0 contains an unquoted service path vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36987</guid>
    <pubDate>Wed, 28 Jan 2026 13:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36987</strong></p>
  <p>Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36986 – Prey 1.9.6 contains an unquoted service path vulnerability that allows local use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36986</guid>
    <pubDate>Wed, 28 Jan 2026 13:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36986</strong></p>
  <p>Prey 1.9.6 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the CronService to insert malicious code that would execute during application startup or system reboot.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36985 – IP Watcher 3.0.0.30 contains an unquoted service path vulnerability in its Windo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36985</guid>
    <pubDate>Wed, 28 Jan 2026 13:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36985</strong></p>
  <p>IP Watcher 3.0.0.30 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated LocalSystem privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36984 – EPSON 1.124 contains an unquoted service path vulnerability in the SENADB servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36984</guid>
    <pubDate>Wed, 28 Jan 2026 13:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36984</strong></p>
  <p>EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject malicious executables that will run with LocalSystem permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36983 – Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36983</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36983</strong></p>
  <p>Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code during service startup. Attackers can exploit the misconfigured service binary path to inject malicious executables with elevated LocalSystem privileges during system boot or service restart.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36982 – Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36982</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36982</strong></p>
  <p>Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperService.exe service that allows local users to potentially inject malicious code. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with elevated system privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36981 – Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36981</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36981</strong></p>
  <p>Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in ForwardDaemon.exe to inject malicious code that will execute with elevated system privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36980 – SAntivirus IC 10.0.21.61 contains an unquoted service path vulnerability in its ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36980</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36980</strong></p>
  <p>SAntivirus IC 10.0.21.61 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted executable path to inject malicious files in the service binary path, enabling privilege escalation to system-level permissions.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36979 – Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36979</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36979</strong></p>
  <p>Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36977 – Wondershare Driver Install Service contains an unquoted service path vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36977</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36977</strong></p>
  <p>Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to LocalSystem account.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36976 – Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36976</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36976</strong></p>
  <p>Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36975 – EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36975</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36975</strong></p>
  <p>EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common Files\EPSON\EPW!3SSRP\E_S60RPB.EXE' to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36974 – Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36974</guid>
    <pubDate>Tue, 27 Jan 2026 19:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36974</strong></p>
  <p>Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files\IDT\WDM\AESTSr64.exe' to inject malicious code that would execute during service startup or system reboot.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36959 – IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36959</guid>
    <pubDate>Mon, 26 Jan 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36959</strong></p>
  <p>IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the STacSV service to inject malicious code that would execute with LocalSystem account permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36958 – Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteSe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36958</guid>
    <pubDate>Mon, 26 Jan 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36958</strong></p>
  <p>Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious executables and escalate privileges on the system.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36957 – PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36957</guid>
    <pubDate>Mon, 26 Jan 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36957</strong></p>
  <p>PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36953 – MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36953</guid>
    <pubDate>Mon, 26 Jan 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36953</strong></p>
  <p>MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36952 – IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36952</guid>
    <pubDate>Mon, 26 Jan 2026 16:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36952</strong></p>
  <p>IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36937 – Microvirt MEMU Play 3.7.0 contains an unquoted service path vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36937</guid>
    <pubDate>Sun, 25 Jan 2026 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36937</strong></p>
  <p>Microvirt MEMU Play 3.7.0 contains an unquoted service path vulnerability in the MEmusvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with elevated LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36936 – Magic Mouse 2 Utilities 2.20 contains an unquoted service path vulnerability in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36936</guid>
    <pubDate>Sun, 25 Jan 2026 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36936</strong></p>
  <p>Magic Mouse 2 Utilities 2.20 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to inject malicious executables and gain elevated system privileges by placing a malicious file in the service path.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36935 – KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36935</guid>
    <pubDate>Sun, 25 Jan 2026 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36935</strong></p>
  <p>KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service KMSELDI configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\KMSpico\Service_KMS.exe to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36934 – Deep Instinct Windows Agent 1.2.24.0 contains an unquoted service path vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36934</guid>
    <pubDate>Sun, 25 Jan 2026 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36934</strong></p>
  <p>Deep Instinct Windows Agent 1.2.24.0 contains an unquoted service path vulnerability in the DeepNetworkService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepNetworkService.exe to inject malicious code that would execute with LocalSystem permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36933 – HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the Pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36933</guid>
    <pubDate>Sun, 25 Jan 2026 14:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36933</strong></p>
  <p>HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47898 – Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47898</guid>
    <pubDate>Fri, 23 Jan 2026 17:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47898</strong></p>
  <p>Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in intermediate directories to gain elevated system access.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47896 – PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47896</guid>
    <pubDate>Fri, 23 Jan 2026 17:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47896</strong></p>
  <p>PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service binary location to inject malicious executables that will be run with elevated LocalSystem privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47890 – LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47890</guid>
    <pubDate>Fri, 23 Jan 2026 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47890</strong></p>
  <p>LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service running with LocalSystem privileges. Attackers can exploit the unquoted path to place malicious executables in intermediate directories, potentially gaining elevated system access during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47889 – Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47889</guid>
    <pubDate>Fri, 23 Jan 2026 17:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47889</strong></p>
  <p>Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in the SoftrosSpellChecker service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Softros Systems\Softros Messenger\Spell Checker\' to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47887 – OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47887</guid>
    <pubDate>Wed, 21 Jan 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47887</strong></p>
  <p>OKI Print Job Accounting 4.4.10 contains an unquoted service path vulnerability in the OkiJaSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Print Job Accounting\' to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47886 – Pingzapper 2.3.1 contains an unquoted service path vulnerability in the Pingzapp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47886</guid>
    <pubDate>Wed, 21 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47886</strong></p>
  <p>Pingzapper 2.3.1 contains an unquoted service path vulnerability in the PingzapperSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Pingzapper\PZService.exe' to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47884 – OKI Configuration Tool 1.6.53 contains an unquoted service path vulnerability in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47884</guid>
    <pubDate>Wed, 21 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47884</strong></p>
  <p>OKI Configuration Tool 1.6.53 contains an unquoted service path vulnerability in the OKI Local Port Manager service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Common\extend3\portmgrsrv.exe' to inject malicious executables and escalate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47883 – Sandboxie Plus 0.7.2 contains an unquoted service path vulnerability in the Sbie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47883</guid>
    <pubDate>Wed, 21 Jan 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47883</strong></p>
  <p>Sandboxie Plus 0.7.2 contains an unquoted service path vulnerability in the SbieSvc service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions during service startup.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47883">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
