Unquoted Service Path Vulnerability in NETGATE Registry Cleaner by NETGATE
CVE-2016-20057
Key Information:
- Vendor
Netgate
- Status
- Vendor
- CVE Published:
- 4 April 2026
Badges
What is CVE-2016-20057?
In NETGATE Registry Cleaner build 16.0.205, an unquoted service path issue exists within the NGRegClnSrv service. This vulnerability allows local attackers to escalate their privileges by exploiting the improperly quoted binary path. By placing a malicious executable in the unquoted path, an attacker can trigger a service restart or system reboot, thereby executing the code with elevated LocalSystem privileges. This poses a significant risk to system integrity and security.
Affected Version(s)
NETGATE Registry Cleaner 16.0.205
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
