Security Advisory
CVE-2020-36975
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in C:Program FilesCommon FilesEPSONEPW!3SSRPE_S60RPB.EXE to inject malicious executables and escalate privileges.