Unquoted Service Path Vulnerability in Windows Firewall Control by Binisoft
CVE-2016-20091

8.5HIGH

Key Information:

Vendor

Binisoft

Vendor
CVE Published:
19 June 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2016-20091?

Windows Firewall Control version 4.8.6.0 is affected by an unquoted service path vulnerability that could allow local attackers to escalate privileges. By inserting malicious executables into unquoted directories within the service path, an attacker can execute these files with LocalSystem privileges when the wfcs.exe service is restarted or the system is rebooted. This poses a significant risk as it gives unauthorized access to higher-level system controls, potentially leading to further exploitation.

Affected Version(s)

Windows Firewall Control 4.8.6.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

zaeek@protonmail.com
.