PT-2026-5294 · 10 Strike · 10-Strike Bandwidth Monitor
Bobby Cooke
·
Published
2026-01-29
·
Updated
2026-01-29
·
CVE-2020-37021
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
10-Strike Bandwidth Monitor version 3.9
Description
The software contains an unquoted service path vulnerability in multiple services. This allows local attackers to escalate privileges by placing a malicious executable in specific file path locations, achieving privilege escalation to SYSTEM during service startup.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, carefully monitor file system changes in the service path locations for unexpected or unauthorized executables.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
10-Strike Bandwidth Monitor