CVE-2020-36933: Htc Iptinstaller

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges.

Affected products

  • Htc Iptinstaller: version 4.0.9 only

Published 2026-01-25. Last modified 2026-06-17.