Official Product Homepageproduct
http://www.netgate.sk/ CVE-2016-20058
HIGH
Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation
Record summary
CVE-2016-20058 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
NETGATE AMITI AntivirusBrowse Netgate / NETGATE AMITI Antivirus | CVE List | 23.0.305 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBNETGATE AMITI Antivirus 23.0.305 - Unquoted Service Path Privilege EscalationExploitDB exploitby Amir.ghtNot analyzed1 file
References
5Product Referenceproduct
http://www.netgate.sk/download/download.php?id=11 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20058 ExploitDB-40540exploit
https://www.exploit-db.com/exploits/40540 VulnCheck Advisory: Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/netgate-amiti-antivirus-build-unquoted-service-path-privilege-escalation