Popcorn Time 6.2 - 'Update service' Unquoted Service Path
Vulnerability Description
Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37059
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Uriel Yochpaz & Jonatan Schor
Affected Vendor
Getpopcorntime
View all reports →