CVE-2020-37021

Severity CVSS v4.0:
HIGH
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
29/01/2026
Last modified:
29/01/2026

Description

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.