CVE-2020-36927
DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse Enterprise\bin\diskpls.exe' to inject malicious executables and escalate privileges.
- Affected products
- Diskpulse
- Flexense Diskpulse
- = 13.6.14
- Fix
- Available
- CVSS 4.0
- 8.5 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.2% (12th percentile)
- Weakness
- CWE-428
- NVD status
- Analyzed
- Published
- 2026-01-15
CVE-2020-36927 at NVD
No indexed exploits for CVE-2020-36927 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-36927 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.