Product Referenceproduct
http://dl.sheedantivirus.ir/setup.exe CVE-2016-20061
HIGH
sheed AntiVirus 2.3 Unquoted Service Path Privilege Escalation
Record summary
CVE-2016-20061 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
sheed AntiVirusBrowse Sheedantivirus / sheed AntiVirus | CVE List | 2.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSheed AntiVirus 2.3 - Unquoted Service Path Privilege EscalationExploitDB exploitby Amir.ghtNot analyzed1 file
References
5Official Product Homepageproduct
http://sheedantivirus.ir/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20061 ExploitDB-40497exploit
https://www.exploit-db.com/exploits/40497 VulnCheck Advisory: sheed AntiVirus 2.3 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/sheed-antivirus-unquoted-service-path-privilege-escalation