Global Registration Service 1.0.0.3 - 'GREGsvc.exe' Unquoted Service Path
Vulnerability Description
Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-36976
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Emmanuel Lujan
References
More from Acer
View All →Affected Vendor
Acer
View all reports →