ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-36879

Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.
8.5
CVSS
5.9
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorLocal
ComplexityLow
RequirementsNone
PrivilegesNone
User InteractionPassive
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusUnavailable

Change Log
DateSourceChangesScore
2026-07-21cve.orginitial, patch: Unavailable5.9

Affected Software
VendorProductVersion
FlexsenseDiskBoss11.7.28
FlexsenseDiskBoss Enterprise11.7.28
FlexsenseDiskBoss Pro11.7.28
FlexsenseDiskBoss Server11.7.28
FlexsenseDiskBoss Ultimate11.7.28
Published: 2025-12-05