PT-2026-4999 · Acer · Global Registration Service
Emmanuel Lujan
·
Published
2026-01-27
·
Updated
2026-01-27
·
CVE-2020-36976
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Acer Global Registration Service version 1.0.0.3
Description
An unquoted service path exists in the service configuration. Local users can exploit the unquoted path in 'C:Program Files (x86)AcerRegistration' to inject malicious executables. These executables would run with elevated LocalSystem privileges during service startup, potentially leading to arbitrary code execution.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Global Registration Service