
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-37017 is an unquoted service path vulnerability in Wibu-Systems CodeMeter version 6.60 that allows local users with low privileges to potentially execute arbitrary code with elevated (LocalSystem) privileges. The vulnerability was formally published on January 29, 2026, and is assigned by VulnCheck. It affects the CodeMeter Runtime Server service on Windows systems. The CVSS v3.1 base score is 7.8 (High), and the CVSS v4.0 base score is 8.5 (High) (VulnCheck Advisory, Feedly).
The root cause is classified as CWE-428 (Unquoted Search Path or Element). When the CodeMeter Runtime Server service is configured with an unquoted binary path containing spaces, Windows' service control manager may resolve the path ambiguously, allowing an attacker to place a malicious executable in a directory that is evaluated before the legitimate binary. Exploitation requires local access and low-level privileges — no user interaction is needed. A public proof-of-concept exploit is available on Exploit-DB (EDB-ID 48735) (Exploit-DB, VulnCheck Advisory).
Successful exploitation allows a local attacker to escalate privileges to LocalSystem, the highest privilege level on a Windows host, enabling full control over the affected system. This includes the ability to read, modify, or delete any file, install software, create new accounts, and potentially pivot to other systems on the network. Confidentiality, integrity, and availability are all rated as High impact (VulnCheck Advisory, Feedly).
A public proof-of-concept exploit has been available on Exploit-DB since 2020 (EDB-ID 48735), making this vulnerability accessible to low-skilled attackers with local access. The EPSS score is approximately 0.011% (0.000110), indicating a low probability of active exploitation in the near term. There is no current evidence of in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Exploit-DB, Feedly).
sc qc CodeMeter or wmic service get name,pathname,startmode to enumerate service paths and confirm the unquoted path vulnerability.C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe).C:\Program.exe or C:\Program Files\CodeMeter.exe) using tools like icacls.C:\Program.exe).C:\Program.exe, C:\Program Files\CodeMeter.exe); new or modified files in CodeMeter installation directories.services.exe.SYSTEM that are not part of the standard CodeMeter installation; child processes of services.exe that are not CodeMeter.exe.HKLM\SYSTEM\CurrentControlSet\Services\CodeMeter registry key, particularly the ImagePath value (Exploit-DB).The primary remediation is to upgrade CodeMeter Runtime to a version later than 6.60 that corrects the unquoted service path. As an immediate workaround, administrators can manually edit the service registry key (HKLM\SYSTEM\CurrentControlSet\Services\CodeMeter\ImagePath) to enclose the binary path in double quotation marks, eliminating the path ambiguity. Additionally, restrict write permissions on directories in the service path to prevent non-privileged users from placing malicious executables. Consult the Wibu-Systems product page for the latest patched runtime version (Wibu-Systems, VulnCheck Advisory).
Coverage of CVE-2020-37017 has been limited to vulnerability database aggregators and security blogs following its formal NVD publication in January 2026. No significant vendor statements, notable researcher commentary, or major media coverage has been identified beyond standard CVE tracking and the original Exploit-DB submission (ctrlaltnod.com, infinitsec.net).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."