CVE-2020-36976

Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Acer Global Registration Service 1.0.0.3 contiene una vulnerabilidad de ruta de servicio sin comillas en su configuración de servicio que permite a usuarios locales ejecutar potencialmente código arbitrario. Los atacantes pueden explotar la ruta sin comillas en C:\Program Files (x86)\Acer\Registration\ para inyectar ejecutables maliciosos que se ejecutarían con privilegios elevados de LocalSystem durante el inicio del servicio.

29 Jan 2026, 17:16

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/49142 - () https://www.exploit-db.com/exploits/49142 -

27 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 19:16

Updated : 2026-04-15 00:35


NVD link : CVE-2020-36976

Mitre link : CVE-2020-36976

CVE.ORG link : CVE-2020-36976


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element