


Perceptive Security
SOC/SIEM Consultancy

SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attac…
Published:
31 januari 2026 om 23:00:00
Alert date:
1 februari 2026 om 16:03:01
Source:
nvd.nist.gov
Security Tools, Operating Systems
CVE-2020-37055 is an unquoted service path vulnerability in SpyHunter 4 security software. The vulnerability allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit this by placing malicious executables in specific file system locations. The malicious code executes with elevated privileges during service startup. This is a local privilege escalation vulnerability that affects the SpyHunter 4 service configuration. The vulnerability requires local access to exploit but can lead to complete system compromise.
Technical details
Mitigation steps:
Affected products:
SpyHunter 4
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2020-37055
https://www.enigmasoftware.com
https://www.exploit-db.com/exploits/48172
https://www.vulncheck.com/advisories/spyhunter-spyhunter-service-unquoted-service-path
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
