Security Advisory
CVE-2020-37060
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named Program.exe to gain persistent system-level access.