Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.

Project Subscriptions

Vendors Products
Getpopcorntime Subscribe
Popcorn Time Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Getpopcorntime
Getpopcorntime popcorn Time
Vendors & Products Getpopcorntime
Getpopcorntime popcorn Time

Fri, 30 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Description Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.
Title Popcorn Time 6.2 - 'Update service' Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-30T16:33:54.229Z

Reserved: 2026-01-28T18:18:30.526Z

Link: CVE-2020-37059

cve-icon Vulnrichment

Updated: 2026-01-30T16:33:51.656Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-30T17:16:12.043

Modified: 2026-02-04T16:34:21.763

Link: CVE-2020-37059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-02T09:27:37Z

Weaknesses