CVE-2016-20060
HIGHHotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20060. PoCs published by Amir.ght.
AI-analyzed exploit summary This is a technical writeup describing an unquoted service path privilege escalation vulnerability in Hotspot Shield. The vulnerability allows a local attacker to escalate privileges by inserting a malicious executable in the service path, which gets executed upon service restart or system reboot.
Description
Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious code executes with LocalSystem privileges.
Exploits (1)
This is a technical writeup describing an unquoted service path privilege escalation vulnerability in Hotspot Shield. The vulnerability allows a local attacker to escalate privileges by inserting a malicious executable in the service path, which gets executed upon service restart or system reboot.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H