Official Product Homepageproduct
http://www.networkdls.com/ CVE-2016-20087
HIGH
Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege
Record summary
CVE-2016-20087 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the service binary path. Attackers can insert malicious executables in the system root path that execute with SYSTEM privileges during service startup or system reboot.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Fortitude HTTPBrowse Networkdls / Fortitude HTTP | CVE List | 1.0.4.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBFortitude HTTP 1.0.4.0 - Unquoted Service Path Privilege EscalationExploitDB exploitby TulpaNot analyzed1 file
References
5Product Referenceproduct
http://www.networkdls.com/Software/View/Fortitude_HTTP nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20087 ExploitDB-40461exploit
https://www.exploit-db.com/exploits/40461 VulnCheck Advisory: Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of PrivilegeThird-party advisory
https://www.vulncheck.com/advisories/fortitude-http-unquoted-service-path-elevation-of-privilege