CVE-2016-6914

HIGH

UniFi Video < 3.8.0 - Local Privilege Escalation via Weak Installation Directory Permissions

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2016-6914. PoCs published by Julien Ahrens, CybermonkX.

AI-analyzed exploit summary The advisory describes a local privilege escalation vulnerability in Ubiquiti UniFi Video for Windows, where insufficient directory permissions allow unprivileged users to place a malicious executable in the application directory, which is then executed with SYSTEM privileges by the service.

Description

Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.

Exploits (2)

exploitdb WRITEUP
by Julien Ahrens · textlocalwindows
https://www.exploit-db.com/exploits/43390

The advisory describes a local privilege escalation vulnerability in Ubiquiti UniFi Video for Windows, where insufficient directory permissions allow unprivileged users to place a malicious executable in the application directory, which is then executed with SYSTEM privileges by the service.

Classification
Writeup 100%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Ubiquiti UniFi Video (Windows) versions 3.7.3, 3.7.0, 3.2.2, and older
Auth required
Prerequisites: Local access to the system · Low-privileged user account
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by CybermonkX · poc
https://github.com/CybermonkX/CVE-2016-6914-UniFiVideo-LPE

This repository contains a functional proof-of-concept exploit for CVE-2016-6914, a local privilege escalation vulnerability in Ubiquiti UniFi Video 3.7.3. The exploit replaces a trusted binary (taskkill.exe) with a malicious payload to achieve SYSTEM-level command execution.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Ubiquiti UniFi Video 3.7.3
Auth required
Prerequisites: Low-privileged access to the target system · Ability to replace the taskkill.exe binary in C:\ProgramData\unifi-video\ · Restart of the UniFi Video Service
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102278
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2017/Dec/83
Issue Tracking, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/140793
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43390/

Scores

CVSS v3 7.8
EPSS 0.0116
EPSS Percentile 63.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-276
Status published
Products (1)
ui/unifi_video < 3.8.0
Published Dec 27, 2017
Tracked Since Feb 18, 2026