CVE-2016-20095
HIGHMatrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2016-20095. PoCs published by Roland C. Redl.
AI-analyzed exploit summary This exploit demonstrates an unquoted service path vulnerability in Matrix42 Remote Control Host, allowing local privilege escalation by placing a malicious executable in a path that the service executes without quotes. The PoC involves copying a file to a specific directory and renaming it to exploit the service's execution path.
Description
Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted name to be executed by the service during startup, gaining elevated privileges.
Exploits (1)
This exploit demonstrates an unquoted service path vulnerability in Matrix42 Remote Control Host, allowing local privilege escalation by placing a malicious executable in a path that the service executes without quotes. The PoC involves copying a file to a specific directory and renaming it to exploit the service's execution path.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H