CVE-2016-20092

HIGH

NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20092. PoCs published by Tulpa.

AI-analyzed exploit summary This is a technical writeup detailing an unquoted service path vulnerability in NetDrive 2.6.12, which could allow local privilege escalation (LPE) due to the service path being unquoted and running with SYSTEM privileges.

Description

NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that will be executed during service startup or system reboot, resulting in privilege escalation.

Exploits (1)

exploitdb WRITEUP
by Tulpa · textlocalwindows
https://www.exploit-db.com/exploits/40422

This is a technical writeup detailing an unquoted service path vulnerability in NetDrive 2.6.12, which could allow local privilege escalation (LPE) due to the service path being unquoted and running with SYSTEM privileges.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: NetDrive 2.6.12
Auth required
Prerequisites: Local access to the system · Ability to place executable in the system root path
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-40422
https://www.exploit-db.com/exploits/40422
Product product
Official Product Homepage
http://www.netdrive.net/
Product product
Product Reference
http://www.netdrive.net/download
Third Party Advisory third-party-advisory
VulnCheck Advisory: NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege
https://www.vulncheck.com/advisories/netdrive-unquoted-service-path-elevation-of-privilege

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Netdrive/NetDrive 2.6.12
Published Jun 19, 2026
Tracked Since Jun 19, 2026