CVE-2016-20091

HIGH

Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20091. PoCs published by zaeek.

AI-analyzed exploit summary This is a technical writeup describing an unquoted service path vulnerability in Windows Firewall Control 4.8.6.0, which can lead to local privilege escalation. The author provides details on the vulnerability and a proof-of-concept demonstration using the `sc qc` command to show the unquoted path.

Description

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

Exploits (1)

exploitdb WRITEUP VERIFIED
by zaeek · textlocalwindows
https://www.exploit-db.com/exploits/40443

This is a technical writeup describing an unquoted service path vulnerability in Windows Firewall Control 4.8.6.0, which can lead to local privilege escalation. The author provides details on the vulnerability and a proof-of-concept demonstration using the `sc qc` command to show the unquoted path.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Windows Firewall Control 4.8.6.0
Auth required
Prerequisites: local access to the system · ability to place an executable in the unquoted path
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-40443
https://www.exploit-db.com/exploits/40443
Product product
Official Product Homepage
http://www.binisoft.org
Third Party Advisory third-party-advisory
VulnCheck Advisory: Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation
https://www.vulncheck.com/advisories/windows-firewall-control-unquoted-service-path-privilege-escalation

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 1.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Binisoft/Windows Firewall Control 4.8.6.0
Published Jun 19, 2026
Tracked Since Jun 19, 2026