CVE-2020-37160

MEDIUM

SprintWork 2.3.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.

Exploits (1)

exploitdb WORKING POC
by boku · textlocalwindows
https://www.exploit-db.com/exploits/48070

Scores

CVSS v3 6.2
EPSS 0.0001
EPSS Percentile 0.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (1)
Veridium/SprintWork 2.3.1
Published Feb 07, 2026
Tracked Since Feb 18, 2026