📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global supply_chain Software Development and Technology HIGH 3h Global apt Government/Critical Infrastructure CRITICAL 5h Global vulnerability Enterprise Software / Data Analytics CRITICAL 5h Global vulnerability Artificial Intelligence and Technology HIGH 9h Global general Technology and Artificial Intelligence MEDIUM 12h Global general Technology and Artificial Intelligence HIGH 13h Global vulnerability Higher Education CRITICAL 22h Global data_breach Government HIGH 23h Global supply_chain Software Development and Open Source Communities CRITICAL 23h Global malware Software Development CRITICAL 23h Global supply_chain Software Development and Technology HIGH 3h Global apt Government/Critical Infrastructure CRITICAL 5h Global vulnerability Enterprise Software / Data Analytics CRITICAL 5h Global vulnerability Artificial Intelligence and Technology HIGH 9h Global general Technology and Artificial Intelligence MEDIUM 12h Global general Technology and Artificial Intelligence HIGH 13h Global vulnerability Higher Education CRITICAL 22h Global data_breach Government HIGH 23h Global supply_chain Software Development and Open Source Communities CRITICAL 23h Global malware Software Development CRITICAL 23h Global supply_chain Software Development and Technology HIGH 3h Global apt Government/Critical Infrastructure CRITICAL 5h Global vulnerability Enterprise Software / Data Analytics CRITICAL 5h Global vulnerability Artificial Intelligence and Technology HIGH 9h Global general Technology and Artificial Intelligence MEDIUM 12h Global general Technology and Artificial Intelligence HIGH 13h Global vulnerability Higher Education CRITICAL 22h Global data_breach Government HIGH 23h Global supply_chain Software Development and Open Source Communities CRITICAL 23h Global malware Software Development CRITICAL 23h
Vulnerabilities

CVE-2020-36933

High
HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with e
CWE-428 — Weakness Type
Published: Jan 25, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges.

🤖 AI Executive Summary

CVE-2020-36933 is a privilege escalation vulnerability in HTC IPTInstaller 4.0.9 affecting the PassThru Service through an unquoted service path. Attackers with local access can inject malicious executables into the service path to achieve code execution with LocalSystem privileges. While no public exploit is available, the vulnerability poses significant risk to organizations using HTC communication solutions, particularly in enterprise environments where service misconfigurations are common.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 27, 2026 05:20
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi government agencies, telecommunications companies (STC, Mobily), and large enterprises using HTC communication infrastructure. Government entities under NCA oversight and SAMA-regulated financial institutions utilizing HTC solutions for internal communications face elevated risk. The vulnerability enables privilege escalation from standard user to LocalSystem, potentially compromising sensitive government communications, financial transaction systems, and critical infrastructure management platforms. Healthcare organizations and energy sector entities (ARAMCO subsidiaries) using HTC systems are also at risk.
🏢 Affected Saudi Sectors
Government Banking and Financial Services Telecommunications Healthcare Energy and Utilities Enterprise Communications
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all systems running HTC IPTInstaller 4.0.9 across your organization
2. Restrict local access to affected systems through access control lists and privileged access management
3. Monitor service startup and binary execution logs for suspicious activity

PATCHING:
1. Upgrade HTC IPTInstaller to version 4.0.10 or later immediately
2. Verify patch installation by checking service path configuration: verify PassThru Service binary path is properly quoted
3. Test functionality in non-production environment before production deployment

COMPENSATING CONTROLS (if immediate patching not possible):
1. Implement application whitelisting on affected systems
2. Restrict write permissions to service installation directories
3. Disable PassThru Service if not actively required
4. Implement file integrity monitoring on service binary paths

DETECTION:
1. Monitor Windows Event Viewer for Service Control Manager events (Event ID 7045) showing service creation/modification
2. Alert on any new executable files created in service paths
3. Monitor process execution with parent process as services.exe
4. Check registry: HKLM\SYSTEM\CurrentControlSet\Services\PassThru for unquoted ImagePath values
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع الأنظمة التي تعمل بـ HTC IPTInstaller 4.0.9 في المنظمة
2. تقييد الوصول المحلي للأنظمة المتأثرة من خلال قوائم التحكم في الوصول وإدارة الوصول المميز
3. مراقبة سجلات بدء الخدمة وتنفيذ الملفات الثنائية للنشاط المريب

التصحيح:
1. ترقية HTC IPTInstaller إلى الإصدار 4.0.10 أو أحدث فوراً
2. التحقق من تثبيت التصحيح بفحص تكوين مسار الخدمة: التحقق من أن مسار الملف الثنائي لخدمة PassThru محاط بعلامات اقتباس بشكل صحيح
3. اختبار الوظائف في بيئة غير الإنتاج قبل نشر الإنتاج

الضوابط البديلة (إذا لم يكن التصحيح الفوري ممكناً):
1. تنفيذ قائمة بيضاء للتطبيقات على الأنظمة المتأثرة
2. تقييد أذونات الكتابة على مجلدات تثبيت الخدمة
3. تعطيل خدمة PassThru إذا لم تكن مطلوبة بنشاط
4. تنفيذ مراقبة سلامة الملفات على مسارات الملفات الثنائية للخدمة

الكشف:
1. مراقبة Windows Event Viewer لأحداث Service Control Manager (معرف الحدث 7045) التي تظهر إنشاء/تعديل الخدمة
2. التنبيه على أي ملفات تنفيذية جديدة تم إنشاؤها في مسارات الخدمة
3. مراقبة تنفيذ العملية مع عملية الوالد كـ services.exe
4. فحص السجل: HKLM\SYSTEM\CurrentControlSet\Services\PassThru للقيم ImagePath غير المحاطة بعلامات اقتباس
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information security policies and procedures A.6.1.1 - Access control policy A.6.2.1 - User registration and de-registration A.8.1.1 - Asset management policy A.12.2.1 - Change management procedures
🔵 SAMA CSF
ID.AM-2 - Software inventory PR.AC-1 - Access control policy PR.AC-4 - Access rights management DE.CM-3 - Personnel activity monitoring RS.MI-2 - Incident response procedures
🟡 ISO 27001:2022
A.5.1 - Management direction for information security A.6.1 - Internal organization A.8.1 - Asset management A.12.2 - Change management A.14.2 - Development and support processes
🟣 PCI DSS v4.0.1
2.2 - Configuration standards for system components 6.2 - Security patches and updates 10.2 - User access logging
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-428
EPSS0.01%
Exploit No
Patch ✓ Yes
Published 2026-01-25
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-428
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.