CVE-2016-20089

HIGH

Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20089. PoCs published by Tulpa.

AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in Iperius Remote 1.7.0, which allows local privilege escalation (LPE) when the service is installed in a path containing spaces. The author provides a clear explanation of the vulnerability, proof via service configuration query, and exploitation steps.

Description

Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation path. When installed from directories containing spaces, attackers can place malicious executables in the path to be executed with elevated privileges during service startup or system reboot.

Exploits (1)

exploitdb WRITEUP
by Tulpa · textlocalwindows
https://www.exploit-db.com/exploits/40427

This is a technical writeup detailing an unquoted service path vulnerability in Iperius Remote 1.7.0, which allows local privilege escalation (LPE) when the service is installed in a path containing spaces. The author provides a clear explanation of the vulnerability, proof via service configuration query, and exploitation steps.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Iperius Remote 1.7.0
Auth required
Prerequisites: Local access to the system · Service installed in a path with spaces · Ability to place executable in the path
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-40427
https://www.exploit-db.com/exploits/40427
Product product
Official Product Homepage
http://www.iperiusremote.com
Product product
Product Reference
https://www.iperiusremote.com/download.aspx
Third Party Advisory third-party-advisory
VulnCheck Advisory: Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege
https://www.vulncheck.com/advisories/iperius-remote-unquoted-service-path-elevation-of-privilege

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 2.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Iperiusremote/Iperius Remote 1.7.0
Published Jun 19, 2026
Tracked Since Jun 19, 2026