CVE-2016-20091

Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by inserting malicious executables in the service path. Attackers can place executable files in unquoted path directories that the wfcs.exe service will execute with LocalSystem privileges upon service restart or system reboot.
Configurations

No configuration.

History

19 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-19 15:16

Updated : 2026-06-22 21:14


NVD link : CVE-2016-20091

Mitre link : CVE-2016-20091

CVE.ORG link : CVE-2016-20091


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element