CVE-2020-36928: Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36928?
CVE-2020-36928 is considered a high severity vulnerability due to its potential for system-level exploitation.
How do I fix CVE-2020-36928?
To fix CVE-2020-36928, ensure that the service path for WBA_Agent_Client is properly quoted in its configuration.
What does CVE-2020-36928 affect?
CVE-2020-36928 affects the Brother BRAgent version 1.38 due to an unquoted service path in the WBA_Agent_Client service.
What are the implications of exploiting CVE-2020-36928?
Exploiting CVE-2020-36928 can allow attackers to execute arbitrary code with LocalSystem privileges.
Is there a patch available for CVE-2020-36928?
As of now, there is no official patch released to address CVE-2020-36928, so implementing workarounds is essential.