CVE-2016-20095 PUBLISHED

Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation

Assigner: VulnCheck
Reserved: 19.06.2026 Published: 19.06.2026 Updated: 19.06.2026

Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted name to be executed by the service during startup, gaining elevated privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Matrix42
Product Matrix42 Remote Control Host
Versions
  • Version 3.20.0031 is affected

Credits

  • Roland C. Redl finder

References

Problem Types

  • Unquoted Search Path or Element CWE