CVE-2020-36976: Global Registration Service 1.0.0.3 - 'GREGsvc.exe' Unquoted Service Path
Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36976?
CVE-2020-36976 has a medium severity rating, as it allows local users to potentially execute arbitrary code.
How do I fix CVE-2020-36976?
To fix CVE-2020-36976, you should modify the service configuration to use a quoted path for the executable.
Which products are affected by CVE-2020-36976?
CVE-2020-36976 affects Acer Global Registration Service version 1.0.0.3.
What type of vulnerability is CVE-2020-36976?
CVE-2020-36976 is an unquoted service path vulnerability that can be exploited by local users.
What can attackers do with CVE-2020-36976?
Attackers can exploit CVE-2020-36976 to potentially execute arbitrary code on affected systems.