CVE-2016-20059
IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local a
CVSS
7.8
High
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Published: Apr 4, 2026 · Last modified: Jul 21, 2026 · CWE-428
0.2%EPSS · 30 days0.2%
2026-06-302026-07-22
IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.
- www.iobit.comhttp://www.iobit.com/downloadcenter.php?product=malware-fighter-free
- www.iobit.comhttp://www.iobit.com/en/index.php
- www.exploit-db.comhttps://www.exploit-db.com/exploits/40525
- www.vulncheck.comhttps://www.vulncheck.com/advisories/iobit-malware-fighter-unquoted-service-path-privilege-escalation
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-9128—0.9%
——0A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.9dCVE-2026-8864—1.4%
——0The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released
to mitigate this potential vulnerability.21dCVE-2016-200617.8 HIG2.5%
——1sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.2dCVE-2016-200607.8 HIG4.8%
——1Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious code executes with LocalSystem privileges.3dCVE-2016-200587.8 HIG50.0%
——15Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.2dCVE-2016-200577.8 HIG45.3%
——14NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.2d