IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the STacSV service to inject malicious code that would execute with LocalSystem account permissions during service startup.
History

Tue, 27 Jan 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Idt
Idt idt Audio
Vendors & Products Idt
Idt idt Audio

Mon, 26 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
Description IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the STacSV service to inject malicious code that would execute with LocalSystem account permissions during service startup.
Title IDT PC Audio 1.0.6499.0 - 'STacSV' Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-26T17:43:15.414Z

Updated: 2026-01-26T20:56:20.051Z

Reserved: 2026-01-26T14:18:25.795Z

Link: CVE-2020-36959

cve-icon Vulnrichment

Updated: 2026-01-26T20:56:16.242Z

cve-icon NVD

Status : Received

Published: 2026-01-26T18:16:26.840

Modified: 2026-01-26T18:16:26.840

Link: CVE-2020-36959

cve-icon Redhat

No data.