CVE-2016-20059

Severity CVSS v4.0:
HIGH
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
04/04/2026
Last modified:
07/04/2026

Description

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.