CVE-2016-20058

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netgate:amiti_antivirus:*:*:*:*:*:*:*:*

History

21 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Netgate AMITI Antivirus compilación 23.0.305 contiene una vulnerabilidad de ruta de servicio sin comillas en los servicios AmitiAvSrv y AmitiAntivirusHealth que permite a los atacantes locales escalar privilegios. Los atacantes pueden colocar un ejecutable malicioso en la ruta de servicio sin comillas y activar el reinicio del servicio o el reinicio del sistema para ejecutar código con privilegios de LocalSystem.

27 Apr 2026, 13:28

Type Values Removed Values Added
References () http://www.netgate.sk/ - () http://www.netgate.sk/ - Product
References () http://www.netgate.sk/download/download.php?id=11 - () http://www.netgate.sk/download/download.php?id=11 - Product
References () https://www.exploit-db.com/exploits/40540 - () https://www.exploit-db.com/exploits/40540 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/netgate-amiti-antivirus-build-unquoted-service-path-privilege-escalation - () https://www.vulncheck.com/advisories/netgate-amiti-antivirus-build-unquoted-service-path-privilege-escalation - Third Party Advisory
First Time Netgate amiti Antivirus
Netgate
CPE cpe:2.3:a:netgate:amiti_antivirus:*:*:*:*:*:*:*:*

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-07-21 07:10


NVD link : CVE-2016-20058

Mitre link : CVE-2016-20058

CVE.ORG link : CVE-2016-20058


JSON object : View

Products Affected

netgate

  • amiti_antivirus
CWE
CWE-428

Unquoted Search Path or Element