Official Product Homepageproduct
http://www.iperiusremote.com/ CVE-2016-20089
HIGH
Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege
Record summary
CVE-2016-20089 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation path. When installed from directories containing spaces, attackers can place malicious executables in the path to be executed with elevated privileges during service startup or system reboot.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Iperius RemoteBrowse Iperiusremote / Iperius Remote | CVE List | 1.7.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBIperius Remote 1.7.0 - Unquoted Service Path Privilege EscalationExploitDB exploitby TulpaNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20089 ExploitDB-40427exploit
https://www.exploit-db.com/exploits/40427 Product Referenceproduct
https://www.iperiusremote.com/download.aspx VulnCheck Advisory: Iperius Remote 1.7.0 Unquoted Service Path Elevation of PrivilegeThird-party advisory
https://www.vulncheck.com/advisories/iperius-remote-unquoted-service-path-elevation-of-privilege