Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands. | |
| Title | Flexsense DiskBoss Service Unquoted Service Path Vulnerability | |
| First Time appeared |
Flexense
Flexense diskboss Flexsense Flexsense diskboss |
|
| Weaknesses | CWE-428 | |
| CPEs | cpe:2.3:a:flexense:diskboss:11.7.28:*:*:*:enterprise:*:*:* cpe:2.3:a:flexsense:diskboss:11.7.28:*:*:*:*:*:*:* |
|
| Vendors & Products |
Flexense
Flexense diskboss Flexsense Flexsense diskboss |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-05T17:18:09.743Z
Reserved: 2025-12-05T13:50:17.242Z
Link: CVE-2020-36879
No data.
Status : Received
Published: 2025-12-05T18:15:53.713
Modified: 2025-12-05T18:15:53.713
Link: CVE-2020-36879
No data.