CVE-2020-37021: 10-Strike Bandwidth Monitor

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

Affected products

  • 10-Strike Bandwidth Monitor: version 3.9 only

Published 2026-01-29. Last modified 2026-06-17.