CVE-2016-20057

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can place a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netgate:registry_cleaner:*:*:*:*:*:*:*:*

History

20 Apr 2026, 14:25

Type Values Removed Values Added
References () http://www.netgate.sk/ - () http://www.netgate.sk/ - Product
References () http://www.netgate.sk/download/download.php?id=4 - () http://www.netgate.sk/download/download.php?id=4 - Product
References () https://www.exploit-db.com/exploits/40539 - () https://www.exploit-db.com/exploits/40539 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/netgate-registry-cleaner-build-unquoted-service-path-privilege-escalation - () https://www.vulncheck.com/advisories/netgate-registry-cleaner-build-unquoted-service-path-privilege-escalation - Third Party Advisory
First Time Netgate
Netgate registry Cleaner
CPE cpe:2.3:a:netgate:registry_cleaner:*:*:*:*:*:*:*:*

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-04-20 14:25


NVD link : CVE-2016-20057

Mitre link : CVE-2016-20057

CVE.ORG link : CVE-2016-20057


JSON object : View

Products Affected

netgate

  • registry_cleaner
CWE
CWE-428

Unquoted Search Path or Element