CVE-2016-20056

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious executables. Attackers can place executable files in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Configurations

No configuration.

History

21 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Spy Emergency build 23.0.205 contiene una vulnerabilidad de ruta de servicio sin comillas en los servicios SpyEmrgHealth y SpyEmrgSrv que permite a atacantes locales escalar privilegios insertando ejecutables maliciosos. Los atacantes pueden colocar archivos ejecutables en la ruta de servicio sin comillas y activar el reinicio del servicio o el reinicio del sistema para ejecutar código con privilegios de LocalSystem.

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-07-21 07:10


NVD link : CVE-2016-20056

Mitre link : CVE-2016-20056

CVE.ORG link : CVE-2016-20056


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element