CVE-2016-20058

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netgate:amiti_antivirus:*:*:*:*:*:*:*:*

History

27 Apr 2026, 13:28

Type Values Removed Values Added
References () http://www.netgate.sk/ - () http://www.netgate.sk/ - Product
References () http://www.netgate.sk/download/download.php?id=11 - () http://www.netgate.sk/download/download.php?id=11 - Product
References () https://www.exploit-db.com/exploits/40540 - () https://www.exploit-db.com/exploits/40540 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/netgate-amiti-antivirus-build-unquoted-service-path-privilege-escalation - () https://www.vulncheck.com/advisories/netgate-amiti-antivirus-build-unquoted-service-path-privilege-escalation - Third Party Advisory
First Time Netgate amiti Antivirus
Netgate
CPE cpe:2.3:a:netgate:amiti_antivirus:*:*:*:*:*:*:*:*

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-04-27 13:28


NVD link : CVE-2016-20058

Mitre link : CVE-2016-20058

CVE.ORG link : CVE-2016-20058


JSON object : View

Products Affected

netgate

  • amiti_antivirus
CWE
CWE-428

Unquoted Search Path or Element