← Back to CVE search

CVE-2016-20059

IObit Malware Fighter

Description

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.

CVSS 7.8EPSS 0.17600000000000002%Risk 0.79
View source
Published
2026-04-04 14:16:18
Affected versions
==4.3.1
Type
Installed app
Last modified
2026-07-21 07:10:00
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H