CVE-2020-36879 Details
Description
Flexsense DiskBoss 11.7.28 allows unauthenticated attackers to elevate their privileges using any of its services, enabling remote code execution during startup or reboot with escalated privileges. Attackers can exploit the unquoted service path vulnerability by specifying a malicious service name in the 'sc qc' command, allowing them to execute arbitrary system commands.
A vulnerability in Flexsense DiskBoss version 11.7.28 allows unauthenticated attackers to elevate privileges through any of its services. This exploitation enables remote code execution during system startup or reboot with escalated rights. The vulnerability arises from an unquoted service path issue, where attackers can inject a malicious service name using the 'sc qc' command to execute arbitrary system commands.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 5, 2025CISA-ADP
Assessed Dec 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.diskboss.com/ | [email protected] | ProductVendor |
| https://www.diskboss.com/downloads.html | [email protected] | ProductVendor |
| https://www.exploit-db.com/exploits/49022 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/flexsense-diskboss-service-unquoted-service-path-vulnerability | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Flexsense DiskBoss | 11.7.28 (semver) |
CPE
Remediation
| |
| Flexsense DiskBoss Pro | All versions |
CPE
Remediation
| |
| Flexsense DiskBoss Ultimate | All versions |
CPE
Remediation
| |
| Flexsense DiskBoss Server | All versions |
CPE
Remediation
| |
| Flexsense DiskBoss Enterprise | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 5, 2025 | New CVE Received | [email protected] |
Volerion