Unquoted Service Path Vulnerability in Matrix42 Remote Control Host by Matrix42
CVE-2016-20095
Key Information:
- Vendor
Matrix42
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2016-20095?
Matrix42 Remote Control Host version 3.20.0031 is vulnerable to an unquoted service path issue in its FastViewerRemoteService and FastViewerRemoteProxy services. This vulnerability allows local users to execute arbitrary code with SYSTEM privileges. By placing a malicious executable within the Program Files directory with a carefully crafted name, attackers can exploit the service startup process to gain elevated access to the system. Users of the affected version should take precautionary measures to secure their environments and consider updating to a patched version.
Affected Version(s)
Matrix42 Remote Control Host 3.20.0031
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
