Description
Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the service's high-level system permissions.
Published: 2026-02-01
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Iskysoft
Iskysoft application Framework Service
Vendors & Products Iskysoft
Iskysoft application Framework Service

Mon, 02 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 01 Feb 2026 14:45:00 +0000

Type Values Removed Values Added
Description Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that would be run with the service's high-level system permissions.
Title Iskysoft Application Framework Service 2.4.3.241 - 'IsAppService' Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Iskysoft Application Framework Service
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-02T18:30:24.234Z

Reserved: 2026-01-28T18:18:30.525Z

Link: CVE-2020-37048

cve-icon Vulnrichment

Updated: 2026-02-02T18:30:14.766Z

cve-icon NVD

Status : Deferred

Published: 2026-02-01T15:16:03.897

Modified: 2026-04-15T00:35:42.020

Link: CVE-2020-37048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-02T09:26:36Z

Weaknesses