CVE-2016-20058
HIGHNetgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20058. PoCs published by Amir.ght.
AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path privilege escalation vulnerability in NETGATE AMITI Antivirus. The vulnerability allows local attackers to escalate privileges by placing a malicious executable in the service path, which gets executed upon service restart or system reboot.
Description
Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Exploits (1)
This is a technical writeup detailing an unquoted service path privilege escalation vulnerability in NETGATE AMITI Antivirus. The vulnerability allows local attackers to escalate privileges by placing a malicious executable in the service path, which gets executed upon service restart or system reboot.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H