PT-2025-49273 · Flexense · Diskboss

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2020-36879

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flexsense DiskBoss version 11.7.28
Description Flexsense DiskBoss version 11.7.28 allows unauthenticated attackers to elevate their privileges by exploiting its services, potentially leading to remote code execution during system startup or reboot with escalated privileges. The issue stems from an unquoted service path, enabling attackers to specify a malicious service name using the 'sc qc' command and execute arbitrary system commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2020-36879

Affected Products

Diskboss