CVE-2020-37021: 10-Strike Bandwidth Monitor
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.
Affected products
- 10-Strike Bandwidth Monitor: version 3.9 only
Published 2026-01-29. Last modified 2026-06-17.