PT-2026-6826 · Microsoft+1 · Windows+1

Boku

·

Published

2026-02-06

·

Updated

2026-02-07

·

CVE-2020-37160

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SprintWork version 2.3.1
Description SprintWork 2.3.1 contains multiple local privilege escalation issues due to insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2020-37160

Affected Products

Sprintwork
Windows