PT-2026-50916 · Unknown · Realtimes Desktop Service

·

CVE-2020-37251

·

Published

2026-06-19

·

Updated

2026-06-23

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RealTimes Desktop Service version 18.1.4
Description An unquoted service path exists in the rpdsvc.exe binary. This allows local attackers to escalate privileges by placing malicious executables in unquoted path directories, which are then executed with LocalSystem privileges during service startup or system reboot. An unquoted service path occurs when a service path contains spaces and is not enclosed in quotation marks, allowing the operating system to potentially execute a different file with a shorter name in the path.
Recommendations Update RealTimes Desktop Service to a version newer than 18.1.4.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-37251

Affected Products

Realtimes Desktop Service