CVE-2016-20059

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:iobit:malware_fighter:*:*:*:*:free:*:*:*

History

No history.

Information

Published : 2026-04-04 14:16

Updated : 2026-07-21 07:10


NVD link : CVE-2016-20059

Mitre link : CVE-2016-20059

CVE.ORG link : CVE-2016-20059


JSON object : View

Products Affected

iobit

  • malware_fighter
CWE
CWE-428

Unquoted Search Path or Element