vendor:
MEMU
by:
SamAlucard
8.8
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: MEMU
Affected Version From: 3.7.0
Affected Version To: 3.7.0
Patch Exists: YES
Related CWE: CVE-2020-27072
CPE: a:microvirt:memu:3.7.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home
2020
MEMU PLAY 3.7.0 – ‘MEmusvc’ Unquoted Service Path
MEMU PLAY 3.7.0 is vulnerable to an unquoted service path vulnerability. An attacker can exploit this vulnerability to gain elevated privileges on the system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of MEMU PLAY 3.7.1 or later.