CVE-2016-20091
HIGHWindows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20091. PoCs published by zaeek.
AI-analyzed exploit summary This is a technical writeup describing an unquoted service path vulnerability in Windows Firewall Control 4.8.6.0, which can lead to local privilege escalation. The author provides details on the vulnerability and a proof-of-concept demonstration using the `sc qc` command to show the unquoted path.
Description
Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.
Exploits (1)
This is a technical writeup describing an unquoted service path vulnerability in Windows Firewall Control 4.8.6.0, which can lead to local privilege escalation. The author provides details on the vulnerability and a proof-of-concept demonstration using the `sc qc` command to show the unquoted path.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H