CVE-2020-37251 PUBLISHED

RealTimes Desktop Service 18.1.4 Unquoted Service Path Privilege Escalation

Assigner: VulnCheck
Reserved: 19.06.2026 Published: 19.06.2026 Updated: 19.06.2026

RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system reboot.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Real
Product RealTimes Desktop Service
Versions
  • Version 18.1.4 is affected

Credits

  • Erick Galindo finder

References

Problem Types

  • Unquoted Search Path or Element CWE