PT-2026-5578 · Iskysoft · Iskysoft Application Framework Service

Alejandro Reyes

·

Published

2026-02-01

·

Updated

2026-02-01

·

CVE-2020-37048

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Iskysoft Application Framework Service version 2.4.3.241
Description The software contains an unquoted service path issue that may allow local users to execute arbitrary code with elevated privileges. An attacker can exploit the unquoted path in the service configuration to inject malicious executables, which would then run with the service’s high-level system permissions.
Recommendations Apply appropriate quoting to the service path to prevent the execution of unauthorized code.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2020-37048

Affected Products

Iskysoft Application Framework Service