ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36935”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36935
Published
2026-01-25
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service KMSELDI configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\KMSpico\Service_KMS.exe to inject malicious executables and escalate privileges.