---
id: CVE-2020-37253
title: >-
  Winstep 18.06.0096 contains an unquoted service path vulnerability in the
  Winstep Xtreme Service that allows local attackers to escalate privileges
summary: >-
  Winstep 18.06.0096 contains an unquoted service path vulnerability in the
  Winstep Xtreme Service that allows local attackers to escalate privileges.
  Attackers can place malicious executables in the Program Files directory to be
  executed …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
published: '2026-06-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T09:10:00.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37253'
references:
  - url: 'https://www.exploit-db.com/exploits/49004'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/winstep-unquoted-service-path-privilege-escalation
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00157
epssPercentile: 0.04132
ingestedAt: '2026-09-29T09:30:49.076Z'
---

## Overview

Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attackers to escalate privileges. Attackers can place malicious executables in the Program Files directory to be executed with LocalSystem privileges when the service starts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
