CVE-2016-20059 HIGH

CVE-2016-20059: IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation

Vendor Iobit
Product IObit Malware Fighter
Weakness CWE-428
Published April 4, 2026
Last update April 6, 2026

CVSS base score

8.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.

Key dates

02Disclosure timeline

April 4, 2026 CVE published
April 6, 2026 Record updated