nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20060 CVE-2016-20060
HIGH
Hotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation
Record summary
CVE-2016-20060 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious code executes with LocalSystem privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Hotspot ShieldBrowse Hotspotshield / Hotspot Shield | CVE List | 6.0.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBHotspot Shield 6.0.3 - Unquoted Service Path Privilege EscalationExploitDB exploitby Amir.ghtNot analyzed1 file
References
5ExploitDB-40528exploit
https://www.exploit-db.com/exploits/40528 Official Product Homepageproduct
https://www.hotspotshield.com/ Product Referenceproduct
https://www.hotspotshield.com/download VulnCheck Advisory: Hotspot Shield 6.0.3 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/hotspot-shield-unquoted-service-path-privilege-escalation