10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

Project Subscriptions

Vendors Products
10-strike Subscribe
Bandwidth Monitor Subscribe
Nsasoft Subscribe
Network Bandwidth Monitor Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Nsasoft
Nsasoft network Bandwidth Monitor
CPEs cpe:2.3:a:nsasoft:network_bandwidth_monitor:3.9:*:*:*:*:*:*:*
Vendors & Products Nsasoft
Nsasoft network Bandwidth Monitor

Fri, 30 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared 10-strike
10-strike bandwidth Monitor
Vendors & Products 10-strike
10-strike bandwidth Monitor

Thu, 29 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description 10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.
Title Bandwidth Monitor 3.9 - 'Svc10StrikeBandMontitor' Unquoted Service Path
Weaknesses CWE-428
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-05T01:27:30.723Z

Reserved: 2026-01-28T18:18:30.522Z

Link: CVE-2020-37021

cve-icon Vulnrichment

Updated: 2026-01-29T14:55:59.736Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-29T15:16:09.773

Modified: 2026-01-29T16:31:00.867

Link: CVE-2020-37021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-30T08:42:46Z

Weaknesses