Record summary

CVE-2016-20093 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.

Description

Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and SpyHunter 4 Service respectively, allowing local users to execute arbitrary code with SYSTEM privileges. Attackers can insert malicious executables in the system root path that execute during service startup or system reboot with elevated privileges.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List4.27affected
CVE List9.29affected

Proofs of concept

1

Catalogued exploits

ExploitDBWise Care 365 4.27 / Wise Disk Cleaner 9.29 - Unquoted Service Path Privilege EscalationExploitDB exploitby TulpaNot analyzed1 file
ExploitDB

PoC details

References

5