VYPR

ShadowMaker

by MiniTool

CVEs (2)

  • CVE-2023-38354HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2020-36953HigJan 26, 2026
    risk 0.51cvss 7.8epss 0.00

    MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject…