Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Description Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.
Title Flexsense DiskBoss Service Unquoted Service Path Vulnerability
First Time appeared Flexense
Flexense diskboss
Flexsense
Flexsense diskboss
Weaknesses CWE-428
CPEs cpe:2.3:a:flexense:diskboss:11.7.28:*:*:*:enterprise:*:*:*
cpe:2.3:a:flexsense:diskboss:11.7.28:*:*:*:*:*:*:*
Vendors & Products Flexense
Flexense diskboss
Flexsense
Flexsense diskboss
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-05T17:18:09.743Z

Reserved: 2025-12-05T13:50:17.242Z

Link: CVE-2020-36879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-05T18:15:53.713

Modified: 2025-12-05T18:15:53.713

Link: CVE-2020-36879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses