CVE-2020-36879 HIGH

CVE-2020-36879: Flexsense DiskBoss Service Unquoted Service Path Vulnerability

Vendor Flexsense
Product DiskBoss
Weakness CWE-428
Published December 5, 2025
Last update December 5, 2025

CVSS base score

8.5/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.

Key dates

02Disclosure timeline

December 5, 2025 CVE published
December 5, 2025 Record updated