Record summary

CVE-2016-20095 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.

Description

Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted name to be executed by the service during startup, gaining elevated privileges.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.20.0031affected

Proofs of concept

1

Catalogued exploits

ExploitDBMatrix42 Remote Control Host 3.20.0031 - Unquoted Path Privilege EscalationExploitDB exploitby Roland C. RedlNot analyzed1 file
ExploitDB

PoC details

References

4