CVE-2020-36879

HIGH

Flexsense DiskBoss 11.7.28 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.

Exploits (1)

exploitdb WRITEUP
by Mohammed Alshehri · textlocalwindows
https://www.exploit-db.com/exploits/49022

Scores

CVSS v4 8.5
EPSS 0.0007
EPSS Percentile 21.3%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (5)
Flexsense/DiskBoss 11.7.28
Flexsense/DiskBoss Enterprise 11.7.28
Flexsense/DiskBoss Pro 11.7.28
Flexsense/DiskBoss Server 11.7.28
Flexsense/DiskBoss Ultimate 11.7.28
Published Dec 05, 2025
Tracked Since Feb 18, 2026