Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 26 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kmspico
Kmspico service Kmseldi |
|
| Vendors & Products |
Kmspico
Kmspico service Kmseldi |
Sun, 25 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service KMSELDI configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\KMSpico\Service_KMS.exe to inject malicious executables and escalate privileges. | |
| Title | KMSpico 17.1.0.0 - 'Service KMSELDI' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-26T13:48:39.533Z
Reserved: 2026-01-25T12:45:06.368Z
Link: CVE-2020-36935
Updated: 2026-01-26T13:48:36.153Z
Status : Deferred
Published: 2026-01-25T14:15:48.167
Modified: 2026-06-17T03:16:32.970
Link: CVE-2020-36935
No data.
OpenCVE Enrichment
Updated: 2026-01-26T11:48:06Z