CVE-2020-37160 PUBLISHED

SprintWork 2.3.1 - Local Privilege Escalation

Assigner: VulnCheck
Reserved: 03.02.2026 Published: 06.02.2026 Updated: 06.02.2026

SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain complete system access.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Veridium
Product SprintWork
Versions
  • Version 2.3.1 is affected

Credits

  • boku finder

References

Problem Types

  • Incorrect Default Permissions CWE