CVE-2016-20089
HIGHIperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20089. PoCs published by Tulpa.
AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in Iperius Remote 1.7.0, which allows local privilege escalation (LPE) when the service is installed in a path containing spaces. The author provides a clear explanation of the vulnerability, proof via service configuration query, and exploitation steps.
Description
Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation path. When installed from directories containing spaces, attackers can place malicious executables in the path to be executed with elevated privileges during service startup or system reboot.
Exploits (1)
This is a technical writeup detailing an unquoted service path vulnerability in Iperius Remote 1.7.0, which allows local privilege escalation (LPE) when the service is installed in a path containing spaces. The author provides a clear explanation of the vulnerability, proof via service configuration query, and exploitation steps.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H