CVE-2020-37254
Received
Received - Intake
Privilege Escalation via Unquoted Service Path in Wondershare PDFelement
Publication date: 2026-06-19
Last updated on: 2026-06-19
Assigner: VulnCheck
Description
Description
Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wondershare | pdfelement | 5.2.9 |
| wondershare | pdfelement | to 5.2.9 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-428 | The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path. |