# CVE-2020-36938

## Summary

- **CVE ID:** CVE-2020-36938
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-732
- **Published:** Jan 27, 2026
- **Last Modified:** Mar 14, 2026

## Description

WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated users to modify system files and executables. Attackers can leverage the overly permissive access controls to potentially modify critical DLLs and executable files in the WinAVR installation directory.

## Affected Products

- WinAVR — WinAVR (20100110)

## References

- [CNA](https://www.exploit-db.com/exploits/49379)
- [CNA](https://sourceforge.net/projects/winavr/)
- [CNA](https://www.vulncheck.com/advisories/winavr-version-insecure-folder-permissions)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.02%
- **EPSS Percentile:** 6.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._