CVE-2020-37060

Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Atomic Alarm Clock 6.3 contiene una vulnerabilidad local de escalada de privilegios en la configuración de su servicio que permite a los atacantes ejecutar código arbitrario con privilegios de SYSTEM. Los atacantes pueden explotar la ruta de servicio sin comillas colocando un ejecutable malicioso llamado 'Program.exe' para obtener acceso persistente a nivel de sistema.

30 Jan 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 17:16

Updated : 2026-04-15 00:35


NVD link : CVE-2020-37060

Mitre link : CVE-2020-37060

CVE.ORG link : CVE-2020-37060


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element