8.5
CVE-2016-20059
- EPSS 0.18%
- Veröffentlicht 04.04.2026 13:51:02
- Zuletzt bearbeitet 27.04.2026 13:27:25
- Quelle disclosure@vulncheck.com
- CVE-Watchlists
- Unerledigt
IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation
IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Iobit ≫ Malware Fighter SwEditionfree Version <= 4.3.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.073 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 8.5 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-428 Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
http://www.iobit.com/en/index.php
https://www.exploit-db.com/exploits/40525
http://www.iobit.com/downloadcenter.php?product=malware-fighter-free
https://www.vulncheck.com/advisories/iobit-malware-fighter-unquoted-service-path-privilege-escalation