PT-2026-25736 · Undefined · Undefined
Published
2026-03-15
·
Updated
2026-03-16
·
CVE-2017-20218
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Serviio PRO version 1.8
Description
The software contains an unquoted search path vulnerability in the Windows service, allowing local users to execute arbitrary code with elevated privileges by placing malicious executables in the system root path. Improper directory permissions grant the Users group full access, enabling authenticated users to replace the executable file with arbitrary binaries, potentially leading to privilege escalation during service startup or system reboot.
Recommendations
Update Serviio PRO to a version that addresses this issue.
Restrict directory permissions to prevent unauthorized modification of executable files.
Ensure the Windows service path is properly quoted to prevent execution of arbitrary code.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined