Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 05 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands. | |
| Title | Flexsense DiskBoss Service Unquoted Service Path Vulnerability | |
| First Time appeared |
Flexense
Flexense diskboss Flexsense Flexsense diskboss |
|
| Weaknesses | CWE-428 | |
| CPEs | cpe:2.3:a:flexense:diskboss:11.7.28:*:*:*:enterprise:*:*:* cpe:2.3:a:flexsense:diskboss:11.7.28:*:*:*:*:*:*:* |
|
| Vendors & Products |
Flexense
Flexense diskboss Flexsense Flexsense diskboss |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-05T17:18:09.743Z
Reserved: 2025-12-05T13:50:17.242Z
Link: CVE-2020-36879
No data.
Status : Received
Published: 2025-12-05T18:15:53.713
Modified: 2025-12-05T18:15:53.713
Link: CVE-2020-36879
No data.
OpenCVE Enrichment
No data.
Weaknesses