PT-2026-6826 · Microsoft+1 · Windows+1

Boku

·

Publicado

2026-02-06

·

Atualizado

2026-02-07

·

CVE-2020-37160

CVSS v3.1

6.2

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SprintWork version 2.3.1
Description SprintWork 2.3.1 contains multiple local privilege escalation issues due to insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Incorrect Default Permissions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-37160

Produtos afetados

Sprintwork
Windows