CVE-2016-20055: IObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege Escalation
IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-20055?
The severity of CVE-2016-20055 is rated high with a score of 8.5.
What type of vulnerability is CVE-2016-20055?
CVE-2016-20055 is an unquoted service path privilege escalation vulnerability.
How do I fix CVE-2016-20055?
To fix CVE-2016-20055, ensure that the service path for AdvancedSystemCareService10 is correctly quoted to prevent privilege escalation.
Who is affected by CVE-2016-20055?
Users of IObit Advanced SystemCare version 10.0.2 are affected by CVE-2016-20055.
What can attackers do with CVE-2016-20055?
Attackers can exploit CVE-2016-20055 to escalate privileges on the affected system by placing a malicious executable in the service path.