Back to CVE List

CVE-2016-20091

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-428
Source
NVD
Vendor
Binisoft
Product
Windows Firewall Control

External References

Discussion (0)

Add Comment

No comments yet. Be the first!