Official Product Homepageproduct
http://www.binisoft.org/ CVE-2016-20091
HIGH
Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation
Record summary
CVE-2016-20091 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Windows Firewall ControlBrowse Binisoft / Windows Firewall Control | CVE List | 4.8.6.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows Firewall Control - Unquoted Service Path Privilege EscalationExploitDB exploitby zaeekNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20091 ExploitDB-40443exploit
https://www.exploit-db.com/exploits/40443 VulnCheck Advisory: Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/windows-firewall-control-unquoted-service-path-privilege-escalation