CVE-2020-37160: Veridium Sprintwork
Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.
SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.
Affected products
- Veridium Sprintwork: version 2.3.1 only
Published 2026-02-07. Last modified 2026-06-17.