CVE-2016-20085
HIGHRealtek High Definition Audio Driver 6.0.1.6730 Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20085. PoCs published by Joey Lane.
AI-analyzed exploit summary This is a technical writeup describing an unquoted service path privilege escalation vulnerability in the Realtek High Definition Audio Driver. It explains the vulnerability mechanics and provides an example of exploitation but does not include functional exploit code.
Description
Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by placing a malicious executable in the service path. Attackers can insert an executable file in the unquoted path and restart the service to execute code with LocalSystem privileges.
Exploits (1)
This is a technical writeup describing an unquoted service path privilege escalation vulnerability in the Realtek High Definition Audio Driver. It explains the vulnerability mechanics and provides an example of exploitation but does not include functional exploit code.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H