Unquoted Service Path Vulnerability in Windows Firewall Control by Binisoft
CVE-2016-20091
Key Information:
- Vendor
Binisoft
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2016-20091?
Windows Firewall Control version 4.8.6.0 is affected by an unquoted service path vulnerability that could allow local attackers to escalate privileges. By inserting malicious executables into unquoted directories within the service path, an attacker can execute these files with LocalSystem privileges when the wfcs.exe service is restarted or the system is rebooted. This poses a significant risk as it gives unauthorized access to higher-level system controls, potentially leading to further exploitation.
Affected Version(s)
Windows Firewall Control 4.8.6.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
