CVE-2020-36984 Details
Description
EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject malicious executables that will run with LocalSystem permissions.
A vulnerability exists in Epson software version 1.124 within the SENADB service, related to an unquoted service path. This flaw enables local attackers to execute code with elevated system privileges. Exploitation involves injecting malicious executables into the unquoted path located in 'C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\'. The injected code would run with LocalSystem permissions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 28, 2026CISA-ADP
Assessed Jan 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.epson.co.uk/support?productID=10820&os=22#drivers_and_manuals | [email protected] | ProductVendor |
| https://www.exploit-db.com/exploits/48965 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/epson-seksmdbexe-unquoted-service-path | [email protected] | AdvisoryBroken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Epson AcuLaser CX17NF-WF | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 28, 2026 | New CVE Received | [email protected] |
Volerion