Unquoted Service Path Vulnerability in Privacy Drive by Cybertron
CVE-2020-37231
Key Information:
- Vendor
Cybertronsoft
- Status
- Vendor
- CVE Published:
- 16 May 2026
Badges
What is CVE-2020-37231?
Privacy Drive 3.17.0 is susceptible to an unquoted service path vulnerability that exists within the pdsvc.exe service binary. This flaw allows local attackers to escalate their privileges by manipulating the service startup process. By placing malicious executables in directories included in the unquoted service path, attackers can execute arbitrary code with LocalSystem privileges, potentially leading to serious security breaches during service startup or system reboot.
Affected Version(s)
Privacy Drive 3.17.0 Build 1456
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
