Security Advisory
CVE-2020-36928
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:Program Files (x86)BrotherBRAgent to inject and execute malicious code with elevated system permissions.