Official Product Homepageproduct
http://www.spy-emergency.com/ CVE-2016-20056
HIGH
Spy Emergency build 23.0.205 Unquoted Service Path Privilege Escalation
Record summary
CVE-2016-20056 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Spy EmergencyBrowse Spy-Emergency / Spy Emergency | CVE List | 23.0.205 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSpy Emergency 23.0.205 - Unquoted Service Path Privilege EscalationExploitDB exploitby Amir.ghtNot analyzed1 file
References
5Product Referenceproduct
http://www.spy-emergency.com/download/download.php?id=1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20056 ExploitDB-40550exploit
https://www.exploit-db.com/exploits/40550 VulnCheck Advisory: Spy Emergency build 23.0.205 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/spy-emergency-build-unquoted-service-path-privilege-escalation