PT-2026-5113 · Unknown · Program Access Controller

Mohammed Alshehri

·

Published

2026-01-28

·

Updated

2026-01-28

·

CVE-2020-36987

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Program Access Controller version 1.2.0.0
Description Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2020-36987

Affected Products

Program Access Controller