Join us January 28th for the first In the Wild with VulnCheck webinar
Register now
Products
Government
Resources
Community
Company
Partners
Sign In / Join
Sign In
Advisories
PDF Complete 3.5.310.2002 - 'pdfsvc.exe' Unquoted Service Path
Go Back
severity
high
date
January 26, 2026
Affecting
PDF Complete <= 3.5.310.2002
CVE
CVE-2020-36957
CWE
CWE-428 Unquoted Search Path or Element
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References
ExploitDB-49226
PDF Complete Vendor Homepage
Credit
Zaira Alquicira
Description
PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.