Record summary

CVE-2016-20092 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.

Description

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.6.12affected

Proofs of concept

1

Catalogued exploits

ExploitDBNetDrive 2.6.12 - Unquoted Service Path Privilege EscalationExploitDB exploitby TulpaNot analyzed1 file
ExploitDB

PoC details

References

5