CVE-2016-20095

HIGH

Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20095. PoCs published by Roland C. Redl.

AI-analyzed exploit summary This exploit demonstrates an unquoted service path vulnerability in Matrix42 Remote Control Host, allowing local privilege escalation by placing a malicious executable in a path that the service executes without quotes. The PoC involves copying a file to a specific directory and renaming it to exploit the service's execution path.

Description

Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted name to be executed by the service during startup, gaining elevated privileges.

Exploits (1)

exploitdb WORKING POC
by Roland C. Redl · textlocalwindows
https://www.exploit-db.com/exploits/39908

This exploit demonstrates an unquoted service path vulnerability in Matrix42 Remote Control Host, allowing local privilege escalation by placing a malicious executable in a path that the service executes without quotes. The PoC involves copying a file to a specific directory and renaming it to exploit the service's execution path.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Matrix42 Remote Control Host 3.20.0031
Auth required
Prerequisites: local access to the system · ability to write to 'C:\Program Files (x86)\Matrix42\'
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-39908
https://www.exploit-db.com/exploits/39908
Product product
Official Product Homepage
https://www.matrix42.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation
https://www.vulncheck.com/advisories/matrix42-remote-control-host-unquoted-path-privilege-escalation

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 2.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-428
Status published
Products (1)
Matrix42/Matrix42 Remote Control Host 3.20.0031
Published Jun 19, 2026
Tracked Since Jun 19, 2026