Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.
CVSS v4.0 Metrics
Exploitability
Attack VectorLocal
ComplexityLow
RequirementsNone
PrivilegesNone
User InteractionPassive
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | cve.org | initial, patch: Unavailable | 5.9 |
Affected Software
| Vendor | Product | Version |
|---|
| Flexsense | DiskBoss | 11.7.28 |
| Flexsense | DiskBoss Enterprise | 11.7.28 |
| Flexsense | DiskBoss Pro | 11.7.28 |
| Flexsense | DiskBoss Server | 11.7.28 |
| Flexsense | DiskBoss Ultimate | 11.7.28 |
Published: 2025-12-05