PT-2026-5578 · Iskysoft · Iskysoft Application Framework Service
Alejandro Reyes
·
Published
2026-02-01
·
Updated
2026-02-01
·
CVE-2020-37048
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Iskysoft Application Framework Service version 2.4.3.241
Description
The software contains an unquoted service path issue that may allow local users to execute arbitrary code with elevated privileges. An attacker can exploit the unquoted path in the service configuration to inject malicious executables, which would then run with the service’s high-level system permissions.
Recommendations
Apply appropriate quoting to the service path to prevent the execution of unauthorized code.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iskysoft Application Framework Service