CVE-2020-37160
MEDIUMSprintWork 2.3.1 - Privilege Escalation
Title source: llmDescription
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.
Exploits (1)
Scores
CVSS v3
6.2
EPSS
0.0000
EPSS Percentile
0.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-276
Status
draft
Timeline
Published
Feb 07, 2026
Tracked Since
Feb 18, 2026