CVE-2020-36881
Severity CVSS v4.0:
HIGH
Type:
CWE-119
Buffer Errors
Publication date:
05/12/2025
Last modified:
05/12/2025
Description
Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to execute arbitrary code on the system. Attackers can exploit this by pasting a specially crafted directory path into the 'Add Input Directory' field.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/x00x00x00x00/diskboss_7.7.14/raw/master/
- https://github.com/x00x00x00x00/diskboss_7.7.14/raw/master/diskboss_setup_v7.7.14.exe
- https://www.diskboss.com/
- https://www.exploit-db.com/exploits/48279
- https://www.vulncheck.com/advisories/flexsense-diskboss-add-input-directory-buffer-overflow



