Security readout for executives and security teams
Plain-English summary
ShareMouse 5.0.43 has a Windows service configuration weakness that can let a local, low-privileged user gain elevated privileges. This is mainly an endpoint hardening and insider/foothold escalation risk, not a remote internet compromise based on the provided sources.
Executive priority
Treat as a high-priority endpoint remediation item where ShareMouse 5.0.43 is deployed, especially on shared workstations or systems with sensitive access. It requires local access, so prioritize alongside controls that prevent initial endpoint compromise.
Technical view
CVE-2020-36991 is a CWE-428 unquoted service path issue in the “ShareMouse Service” for ShareMouse 5.0.43. The CVSS 4.0 score is 8.5, with local attack vector, low complexity, low privileges required, and high confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to systems running ShareMouse 5.0.43 with the affected ShareMouse Service installed. The provided sources do not identify other affected versions or platforms.
Exploitation context
An ExploitDB entry is cited, indicating public exploit information exists. The source bundle does not show CISA KEV listing or confirmed active exploitation, so active exploitation should not be assumed.
Researcher notes
Evidence is limited to the CVE record, VulnCheck advisory, vendor homepage, and ExploitDB reference. No vendor fix details are included in the provided bundle. Do not broaden affected versions beyond ShareMouse 5.0.43 without additional evidence.
Mitigation direction
- Identify endpoints running ShareMouse 5.0.43.
- Check ShareMouse vendor guidance for fixed versions or recommended remediation.
- Update ShareMouse if the vendor provides a corrected release.
- Disable or remove ShareMouse where it is not business-critical.
- Apply least-privilege controls to reduce local user escalation opportunities.
Validation and detection
- Inventory installed ShareMouse versions across managed endpoints.
- Confirm whether the “ShareMouse Service” exists on each system.
- Review the service path configuration for unquoted path exposure.
- Check local user write permissions near the service path.
- Reassess after update, removal, or vendor-recommended remediation.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-428: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupExecution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2020-36991 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 8.5 (4.0)
- Known Exploited
- No
- Published
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N——Primary CVE scoreVulnerability scoring details
Base CVSS 4.0 score
8.5HighVector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source materials
- CVE List V5 sourceCVE List V5
- ExploitDB-48794CVE reference · exploit
- ShareMouse Official Vendor HomepageCVE reference · product
- VulnCheck Advisory: ShareMouse 5.0.43 - 'ShareMouse Service' Unquoted Service PathCVE reference · third-party-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Unquoted Search Path or Element
Unquoted Search Path or Element represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
