CVE-2016-20055

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:iobit:advanced_system_care:*:*:*:*:free:*:*:*

History

14 Apr 2026, 19:09

Type Values Removed Values Added
CPE cpe:2.3:a:iobit:advanced_system_care:*:*:*:*:free:*:*:*
First Time Iobit advanced System Care
Iobit
References () http://www.iobit.com/en/advancedsystemcarefree.php# - () http://www.iobit.com/en/advancedsystemcarefree.php# - Product
References () http://www.iobit.com/en/index.php - () http://www.iobit.com/en/index.php - Product
References () https://www.exploit-db.com/exploits/40577 - () https://www.exploit-db.com/exploits/40577 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/iobit-advanced-systemcare-unquoted-service-path-privilege-escalation - () https://www.vulncheck.com/advisories/iobit-advanced-systemcare-unquoted-service-path-privilege-escalation - Third Party Advisory

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-04-14 19:09


NVD link : CVE-2016-20055

Mitre link : CVE-2016-20055

CVE.ORG link : CVE-2016-20055


JSON object : View

Products Affected

iobit

  • advanced_system_care
CWE
CWE-428

Unquoted Search Path or Element