CVE-2020-37252 PUBLISHED

Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation

Assigner: VulnCheck
Reserved: 19.06.2026 Published: 19.06.2026 Updated: 19.06.2026

Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSystem privileges during service startup or system reboot.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Realtek
Product Realtek Audio Service
Versions
  • Version 1.0.0.55 is affected

Credits

  • Erika Figueroa finder

References

Problem Types

  • Unquoted Search Path or Element CWE