Vulnerability Description
10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.10-strike.com/
- https://www.exploit-db.com/exploits/48591
- https://www.vulncheck.com/advisories/bandwidth-monitor-svcstrikebandmontitor-unq
FAQ
What is CVE-2020-37021?
CVE-2020-37021 is a vulnerability with a CVSS score of 7.8 (HIGH). 10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in s...
How severe is CVE-2020-37021?
CVE-2020-37021 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37021?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.