CVE-2016-20095
Published: 19 June 2026
Summary
CVE-2016-20095 is a high-severity Unquoted Search Path or Element (CWE-428) vulnerability in Matrix42 Remote Control (inferred from references). Its CVSS base score is 8.5 (High).
Operationally, ranked at the 2.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2016-10908
Vulnerability details
Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with…
more
a crafted name to be executed by the service during startup, gaining elevated privileges.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.