PT-2026-4655 · Microvirt · Memu Play

Samalucard

·

Published

2026-01-25

·

Updated

2026-01-25

·

CVE-2020-36937

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microvirt MEMU Play version 3.7.0
Description The software contains an unquoted service path issue in the MEmusvc Windows service. This allows local attackers to potentially execute arbitrary code by exploiting the unquoted binary path to inject malicious executables. Successful exploitation could result in the execution of these executables with elevated LocalSystem privileges.
Recommendations Ensure the service path for MEmusvc is properly quoted to prevent the execution of unauthorized code.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-36937

Affected Products

Memu Play